Standardlikelihood: Mediumseverity: HighDraft

CAPEC-103Clickjacking

Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High

Description

An adversary tricks a victim into unknowingly initiating some action in one system while interacting with the UI from a seemingly completely different, usually an adversary controlled or intended, system. Metadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Underlying weakness: CWE-1021. Related CAPEC pattern: [object Object].

Related weaknesses· 1

CWE-1021

Related attack patterns· 1

CAPEC-173 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Restriction of Rendered UI Layers or Framescwe-1021100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
iFrame Overlay
CAPEC
Action Spoofing
CAPEC
Tapjacking
CAPEC
Session Hijacking
CAPEC
Cross Site Request Forgery
CAPEC
JSON Hijacking (aka JavaScript Hijacking)
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.