Skip to content

Add test2.html to demonstrate insecure postMessage#18

Open
maekuss wants to merge 1 commit into
mainfrom
maekuss-patch-8
Open

Add test2.html to demonstrate insecure postMessage#18
maekuss wants to merge 1 commit into
mainfrom
maekuss-patch-8

Conversation

@maekuss

@maekuss maekuss commented Dec 2, 2025

Copy link
Copy Markdown
Owner

This HTML file demonstrates an insecure postMessage implementation that lacks origin validation, allowing potential cross-site scripting (XSS) attacks.

This HTML file demonstrates an insecure postMessage implementation that lacks origin validation, allowing potential cross-site scripting (XSS) attacks.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant