A Stored XSS vulnerability was reported in the Keycloak Security mailing list, affecting all the versions of Keycloak, including the latest release (16.0.1). The vulnerability allows a privileged attacker to execute malicious scripts in the admin console, abusing of the groups' dropdown functionality.
Successful attacks of this vulnerability can result a privileged attacker to load a XSS script, and steal data from other users. The impact can be considered moderate to low, considering privileged credentials are required.
{
"nvd_published_at": null,
"github_reviewed_at": "2022-11-29T23:55:23Z",
"cwe_ids": [
"CWE-80"
],
"severity": "MODERATE",
"github_reviewed": true
}