Is Whatfix for Infosys safe?
Whatfix for Infosys relays unauthenticated postMessage input on Workday pages into an unrestricted background fetch proxy.
On Workday and myWorkday pages, a content script listens for window postMessage events without checking the sender's origin and forwards API requests to the extension's background service worker. The only validation function there is an unimplemented stub that always returns true, so any page (including an embedded iframe) can direct the extension to fetch an arbitrary URL with attacker-supplied headers and body, and get the response text back.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.