Lucene search

K
cvelistApacheCVELIST:CVE-2019-17557
HistoryMay 04, 2020 - 12:27 p.m.

CVE-2019-17557

2020-05-0412:27:31
apache
www.cve.org

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.0%

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

CNA Affected

[
  {
    "product": "Apache Syncope",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6"
      }
    ]
  }
]

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.0%

Related for CVELIST:CVE-2019-17557