Description
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://syncope.apache.org/security#CVE-2018-17184:_Stored_XSS
Scores
CVSS v3
5.4
EPSS
0.0100
EPSS Percentile
77.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
apache/syncope
2.0.0 - 2.0.11
org.apache.syncope/syncope-core
0 - 2.0.11Maven
Published
Nov 06, 2018
Tracked Since
Feb 18, 2026