CVE-2023-30949
26.07.2023, 18:15
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.Enginsight
Vendor | Product | Version |
---|---|---|
palantir | slate | 𝑥 < 6.207.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1173 - Improper Use of Validation FrameworkThe application does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.
- CWE-346 - Origin Validation ErrorThe software does not properly verify that the source of data or communication is valid.