CVE-2020-11610
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.
Se detectó un problema en xdLocalStorage versiones hasta 2.0.5. La función postData() en el archivo xdLocalStoragePostMessageApi.js especifica el comodín (*) como targetOrigin cuando llama a la función postMessage() en el objeto primario. Por lo tanto, cualquier dominio puede cargar la aplicación que aloja el "magical iframe" y recibe los mensajes que envía el "magical iframe".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-07 CVE Reserved
- 2020-04-07 CVE Published
- 2023-08-11 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/ofirdagan/cross-domain-local-storage | Product |
URL | Date | SRC |
---|---|---|
https://grimhacker.com/exploiting-xdlocalstorage-localstorage-and-postmessage/#Missing-TargetOrigin-Magic-iframe | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cross Domain Local Storage Project Search vendor "Cross Domain Local Storage Project" | Cross Domain Local Storage Search vendor "Cross Domain Local Storage Project" for product "Cross Domain Local Storage" | <= 2.0.5 Search vendor "Cross Domain Local Storage Project" for product "Cross Domain Local Storage" and version " <= 2.0.5" | - |
Affected
|