Vulnerabilities/

xdlocalstorage does not verify request origin

Severity:
High

Description

An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
xdlocalstorage
Anything's wrong? Let us know Last updated on July 17, 2023