#VU23439 Overly permissive cross-domain whitelist in Norton Password Manager - CVE-2019-19545
Published: December 6, 2019
Norton Password Manager
Broadcom
Description
The vulnerability allows a local attacker to bypass the CORS protection mechanism.
The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request. A remote authenticated attacker on local network can supply arbitrary value via the "Origin" HTTP header, bypass implemented CORS protection mechanism and perform cross-site scripting attacks against the vulnerable application.