Data center: Ashburn, VA

Telegram Chat : MBHH_x86

Email Us:

Mobile Hacker For Hire, hire a hacker, hiring a hacker, hacker with proof

Evernote Web Clipper Same-Origin Policy Bypass ≈ Packet Storm

Table of Contents

evernote: extension allows cross-origin iframe communication

I happened to notice that the Evernote Web Clipper (3,000,000+ users) allows any website to bypass the same origin policy.

If you send a message like window.postMessage({type: “EN_request”, name: “EN_SerializeTo”, data: { frameName: id }), the frame DOM is collected and then posted back to the top window.

I made a quick demo exploit:

I notice the evernote website requests that all vulnerabilities are submitted via HackerOne, but I’m unwilling to do that.

I’ll send a report to the Chrome Webstore policy team instead, who can handle contacting the registered developer.

Found by:

Leave a Reply

Your email address will not be published. Required fields are marked *

error: Content is protected !!