Skip to main content

Permissive Cross-domain Policy with Untrusted Domains

CVE-2024-10315

Severity Medium
Score 6.9/10

Summary

In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.

  • LOW
  • NETWORK
  • ACTIVE
  • LOW

CWE-942 - Permissive Cross-domain Policy with Untrusted Domains

The software uses a cross-domain policy file that includes domains that should not be trusted.

References

Advisory Timeline

  • Published