CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
27.3%
Apache Syncope is vulnerable to HTML injection. The vulnerability is due to improper input validation, allowing HTML tags to be added to any text field, leading to potential injections. Attackers can use this to inject malicious HTML or scripts, which could compromise user data and application integrity.
www.openwall.com/lists/oss-security/2024/07/22/3
github.com/advisories/GHSA-8pxv-x6jq-5vw9
github.com/apache/syncope/commit/12e65f5fb12ad87ce0b223b3c2bb39025a4521e4
syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser
www.openwall.com/lists/oss-security/2024/07/22/3