CVE-2020-5497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/01/2020
Last modified:
24/01/2023

Description

The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mitreid:connect:*:*:*:*:*:*:*:* 1.3.3 (including)