Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Taskcafe |
Taskcafe_project |
* |
0.1.0 (excluding) |
References