Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Taskcafe | Taskcafe_project | * | 0.1.0 (excluding) |
References