Lucene search

K
osvGoogleOSV:GHSA-6QJ8-C27W-RP33
HistoryJan 06, 2022 - 7:38 p.m.

Cross-site scripting in Apache Syncome EndUser

2022-01-0619:38:07
Google
osv.dev
10

0.001 Low

EPSS

Percentile

40.0%

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

0.001 Low

EPSS

Percentile

40.0%

Related for OSV:GHSA-6QJ8-C27W-RP33