Количество 2
Количество 2
CVE-2020-11610
An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.
GHSA-mr5m-2385-2vcp
xdlocalstorage does not verify request origin
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-11610 An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends. | CVSS3: 8.8 | 0% Низкий | почти 6 лет назад | |
GHSA-mr5m-2385-2vcp xdlocalstorage does not verify request origin | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу