CVE-2015-9544 Information
Description
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Reference
https://github.com/ofirdagan/cross-domain-local-storage https://github.com/ofirdagan/cross-domain-local-storage/issues/17 https://github.com/ofirdagan/cross-domain-local-storage/pull/19 https://grimhacker.com/exploiting-xdlocalstorage-localstorage-and-postmessage/Missing-Origin-Magic-iframe
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.1
Share on: