Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-9544

An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.8%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 5.8
Products affected by CVE-2015-9544


Contact Us

Shodan ® - All rights reserved