CVE-2019-1010247

MEDIUM

ZmartZone IAM mod_auth_openidc <2.3.10.1 - XSS

Title source: llm
STIX 2.1

Description

ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2.

Scores

CVSS v3 6.1
EPSS 0.0036
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
openidc/mod_auth_openidc < 2.3.10.2
Published Jul 19, 2019
Tracked Since Feb 18, 2026