CVE-2018-17184

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-17184
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-17184.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-17184
Aliases
Published
2018-11-06T19:29:00Z
Modified
2024-09-03T02:06:27.431200Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

References

Affected packages

Git / github.com/apache/syncope

Affected ranges

Type
GIT
Repo
https://github.com/apache/syncope
Events

Affected versions

syncope-2.*

syncope-2.0.0
syncope-2.0.1
syncope-2.0.10
syncope-2.0.2
syncope-2.0.3
syncope-2.0.4
syncope-2.0.5
syncope-2.0.6
syncope-2.0.7
syncope-2.0.8
syncope-2.0.9