H3-2021-0002
Subdomain Takeover
Category | SECURITY_MISCONFIGURATION |
Base Score | 7.5 |
Description
The DNS record for a subdomain has a CNAME record that points to another subdomain that is not in use. Attackers may be able to claim the subdomain that is the CNAME for this subdomain.
Impact
By taking over a legitimate looking company domain, attackers can trick users through phishing campaigns, attempt to steal user cookies and passwords, deface the company web site and damage the company brand.