The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

"Frameable response" scanner rule ignores CSP

Nicolas | Last updated: Jul 15, 2021 12:38PM UTC

The scanner raises a "Frameable response (potential Clickjacking)" issue when the X-Frame-Options header is set incorrectly, even if the frame-ancestors CSP is set to 'none'. While it's still interesting for internal tests to know that X-Frame-Options is used incorrectly, the issue should probably be phrased differently since in this case the page is not frameable.

Uthman, PortSwigger Agent | Last updated: Jul 19, 2021 10:43AM UTC