We found results for “”
CVE-2024-38503
Good to know:
Date: July 22, 2024
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
Language: Java
Severity Score
Related Resources (8)
Severity Score
Top Fix
Upgrade Version
Upgrade to version org.apache.syncope.client.idrepo:syncope-client-idrepo-console:3.0.8
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |