CVE-2024-38503
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
22/07/2024
Last modified:
06/12/2024
Description
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.<br />
The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”.<br />
<br />
Users are recommended to upgrade to version 3.0.8, which fixes this issue.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* | 2.1.0 (including) | 2.1.14 (including) |
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.0.8 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser
- https://www.openwall.com/lists/oss-security/2024/07/22/3
- http://www.openwall.com/lists/oss-security/2024/07/22/3
- https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser