CVE-2024-38503

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
22/07/2024
Last modified:
06/12/2024

Description

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.<br /> The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”.<br /> <br /> Users are recommended to upgrade to version 3.0.8, which fixes this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.14 (including)
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.8 (excluding)