Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mr5m-2385-2vcp

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

xdlocalstorage does not verify request origin

An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.

Пакеты

Наименование

xdlocalstorage

npm
Затронутые версииВерсия исправления

<= 2.0.5

Отсутствует

EPSS

Процентиль: 45%
0.00227
Низкий

8.8 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.

EPSS

Процентиль: 45%
0.00227
Низкий

8.8 High

CVSS3

Дефекты

CWE-668