ZeroHour

CVE-2020-11610

PoC
CVSS 3.1
8.8 high
EPSS
1%p71
Published
()
Modified
Description

An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.

Vendors
cross domain local storage project
Products
cross domain local storage
Weakness
CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.