Substring origin check in xs-utils.js discloses a signed-in customer's account number and session token

This page's origin is
It is a subdomain of whitekbb.com, controlled by the bug bounty tester. It is not operated by Sisal and holds no Sisal certificate. The Sisal page accepts it anyway, because e.origin.indexOf(t) > -1 is a substring test rather than an origin comparison.

Reproduction, in one browser:

  1. Sign in to https://www.sisal.it in this same browser, in another tab.
  2. Click 1. Open the Sisal page below. A popup opens on www.sisal.it. Wait until it has finished loading, about ten seconds.
  3. Click 2. Ask the Sisal page for the credentials.
  4. The account number and session token of the signed-in customer appear below, received from origin https://www.sisal.it.

Log

(nothing has run yet)

The single message this page sends is {"esito":"0","tipoOperazione":"26"}, posted to https://www.sisal.it. The page contains no fetch, no XMLHttpRequest, no sendBeacon, no form submission and no WebSocket. Its source is plain and unminified, so it can be audited with View Source in a few seconds.