Summary

Netsparker detected frame injection, which occurs when a frame on a vulnerable web page displays another web page via a user-controllable input.

Impact
An attacker might use this vulnerability to redirect users to other malicious websites that are used for phishing and similar attacks.
Remediation
  • Where possible do not use users' input for URLs.
  • If you definitely need dynamic URLs, make a list of valid accepted URLs and do not accept other URLs.
  • Ensure that you only accept URLs which are located on accepted domains.
Classifications
PCI v3.1-6.5.1, PCI v3.2-6.5.1, WASC-38, OWASP 2013-A10 , CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N