Количество 2
Количество 2
CVE-2020-11611
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain that is currently loaded within the iframe can receive the messages that the client sends.
GHSA-c6c4-jmqx-3r33
Open Redirect in xdLocalStorage
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-11611 An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain that is currently loaded within the iframe can receive the messages that the client sends. | CVSS3: 6.1 | 0% Низкий | почти 6 лет назад | |
GHSA-c6c4-jmqx-3r33 Open Redirect in xdLocalStorage | CVSS3: 6.1 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу