Permissive Cross-domain Policy with Untrusted Domains
CVE-2024-10315
Summary
In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.
- LOW
- NETWORK
- ACTIVE
- LOW
CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
The software uses a cross-domain policy file that includes domains that should not be trusted.
References
Advisory Timeline
- Published