CVE-2020-11611

CVE-2020-11611

An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain that is currently loaded within the iframe can receive the messages that the client sends.

Source: CVE-2020-11611

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다