Code vulnerable to clickjacking in LWC component

Overview

Clickjacking, also known as a "UI redress attack", is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intended to click on the top-level page. Thus, the attacker is "hijacking" clicks meant for a page and routing them to another page.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Common

Incidence

How common is this issue?
7%2%
arrow down4%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
5 months4 weeks
arrow down81%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconSession SecurityiconSession ManagementiconA04:2021 – Insecure Designicon