OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:openidm_project:openidm:4.5.0:*:*:*:*:*:*:*"
],
"vendor_product": "openidm_project:openidm",
"extracted_events": [
{
"introduced": "4.5.0"
},
{
"last_affected": "4.5.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:openidm_project:openidm:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "4.0.0"
}
]
}