A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.
The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://palantir.safebase.us/?tcuUid=bbc1772c-e10a-45cc-b89f-48cc1a8b2cfc | vendor advisory |