Frame Injection

  • CWE 601
  • WASC 38
  • PCI 3.2-6.5.1
  • OWASP 2017-A1

src attribute of an HTML frame can be controlled by an attacker and website visitors may be redirected to malicious websites that are used for phishing attacks.

References