← Back to CVE List

CVE-2020-11610

Published: 2020-04-07T18:15Z
Last Modified: 2024-11-21T04:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt