It's not an issue on Steemit but may become an issue on other condenser-based sites that take Steemit's frontend and modify it. They can and probably will include iframes and other elements to monetize the portal itself.

Great job testing the parameters. The ecosystem here needs more of that.


Thanks, much appreciated :)

PS. It seems that is vulnerable both to clickjacking and tabnabbing..!

I sent it to the person who runs Thanks.

