Is OmniDefend SSO Extension safe?
OmniDefend SSO Extension accepts forged postMessage tokens without origin validation, allowing any web page to read the Windows username when Windows autologin is configured.
The extension installs a message listener on every HTTP and HTTPS page that gates on a data-field token rather than the message origin. Any page can forge that token and send a request that causes the extension to query a native host for the current Windows username, which is then broadcast back via window.postMessage to all listeners on the page. The exposure occurs only when the Windows autologin feature is active in OmniDefend's server settings.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itSoftex - 1 other listing from the same operator, 1 of them carrying a finding
Softex - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 6k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.