CVE-2023-49111

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/06/2024
Last modified:
04/11/2025

Description

For Kiuwan installations with SSO (single sign-on) enabled, an <br /> unauthenticated reflected cross-site scripting attack can be performed <br /> on the login page "login.html". This is possible due to the request parameter "message" values<br /> being directly included in a JavaScript block in the response. This is <br /> especially critical in business environments using AD SSO <br /> authentication, e.g. via ADFS, where attackers could potentially steal <br /> AD passwords.<br /> <br /> <br /> <br /> This issue affects Kiuwan SAST: