CVE-2023-30949
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.08%
- CWE
- CWE-1173
- Published
- 2023-07-26
- Last modified
- 2026-03-13
Affected products
- Palantir com.palantir.slate:slate
Weakness type
Related vulnerabilities
- CVE-2024-58360 — stoatchat before 0.7.8 Unrestricted Account Creation
- CVE-2026-33674 — PrestaShop: Improper Use of Validation Framework
- CVE-2025-48490 — Laravel Rest Api has a Search Validation Bypass
- CVE-2025-3940 — Improper Use of Validation Framework
- CVE-2022-1414 — 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An...
- CVE-2020-1640 — Junos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.