CVE-2018-17184

MEDIUM

Apache Syncope - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0100
EPSS Percentile 77.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
apache/syncope 2.0.0 - 2.0.11
org.apache.syncope/syncope-core 0 - 2.0.11Maven
Published Nov 06, 2018
Tracked Since Feb 18, 2026