VDB
Sign up
HIGH8.8

GHSA-mr5m-2385-2vcp

xdlocalstorage does not verify request origin

Details

An issue was discovered in xdLocalStorage through 2.0.5. The `postData()` function in `xdLocalStoragePostMessageApi.js` specifies the wildcard (`*`) as the targetOrigin when calling the `postMessage()` function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/xdlocalstorage
Introduced in: 0

No fixed version published yet for xdlocalstorage (npm). Pin to a known-safe version or switch to an alternative.

References