CVE-2023-49111
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
20/06/2024
Last modified:
04/11/2025
Description
For Kiuwan installations with SSO (single sign-on) enabled, an <br />
unauthenticated reflected cross-site scripting attack can be performed <br />
on the login page "login.html". This is possible due to the request parameter "message" values<br />
being directly included in a JavaScript block in the response. This is <br />
especially critical in business environments using AD SSO <br />
authentication, e.g. via ADFS, where attackers could potentially steal <br />
AD passwords.<br />
<br />
<br />
<br />
This issue affects Kiuwan SAST:
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



