| It was identified that the assets contemplated not include security controls adequate to combat the user clicks theft attacks (Click-Jacking). This attack is to load the hosted web application in assets covered with an opaque layer over it, with fake buttons and links, so that clicking on them, the user is actually inadvertently clicking in the web application. This attack is especially dangerous if the user is authenticated on the contemplated web application, because the inadvertent clicks occur in the same area authenticated. |