CVE-2019-17557

CVSS v3.1 5.4 (Medium)
54% Progress
CVSS v2.0 3.5 (Low)
35% Progress
EPSS 0.09 % (40th)
0.09% Progress
Affected Products 1
Advisories 1

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2020-05-04 13:15:11
(4 years ago)
Updated Date
2020-05-07 15:12:00
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Syncope from 2.0.0 version and prior 2.0.15 version cpe:2.3:a:apache:syncope >= 2.0.0 < 2.0.15
  Apache Syncope from 2.1.0 version and prior 2.1.6 version cpe:2.3:a:apache:syncope >= 2.1.0 < 2.1.6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...