Логотип exploitDog
bind:CVE-2024-38503
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-38503

Количество 2

Количество 2

nvd логотип

CVE-2024-38503

больше 1 года назад

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8pxv-x6jq-5vw9

больше 1 года назад

Apache Syncope Improper Input Validation vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-38503

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.

CVSS3: 5.4
3%
Низкий
больше 1 года назад
github логотип
GHSA-8pxv-x6jq-5vw9

Apache Syncope Improper Input Validation vulnerability

CVSS3: 6.5
3%
Низкий
больше 1 года назад

Уязвимостей на страницу