A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the pages content, which could lead to phishing attacks.
The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Slate | Palantir | * | 6.207.0 (excluding) |