apereo.github.ioConfirmation
https://apereo.github.io/2021/10/18/restvuln CVE-2021-42567
MEDIUMNuclei
Cross-site Scripting in Apereo CAS
Record summary
CVE-2021-42567 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
central_authentication_serviceBrowse apereo / central_authentication_service | VulnCheck | Version data not supplied | |
org.apereo.cas:cas-server-core-webBrowse Maven / org.apereo.cas:cas-server-core-web | GitHub Advisory | Before 6.4.2 · Fixed in 6.4.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMApereo CAS Cross-Site ScriptingCVSS 6.1
Apereo CAS through 6.4.1 allows cross-site scripting via POST requests sent to the REST API endpoints.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a victim's browser, potentially leading to session hijacking, data theft, or defacement.
Remediation
Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.
WeaknessesCWE-79
Authorspdteam
Template tagscve2021cveapereoxsscasvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apereo:central_authentication_service:*:*:*:*:*:*:*:*
Shodan: http.title:'CAS - Central Authentication Service'
Shodan: http.title:'cas - central authentication service'
FOFA: title='cas - central authentication service'
Google: intitle:'cas - central authentication service'
https://apereo.github.io/2021/10/18/restvuln/ https://www.sudokaikan.com/2021/12/exploit-cve-2021-42567-post-based-xss.html https://github.com/sudohyak/exploit/blob/dcf04f704895fe7e042a0cfe9c5ead07797333cc/CVE-2021-42567/README.md https://nvd.nist.gov/vuln/detail/CVE-2021-42567 https://github.com/apereo/cas/releases
Source: ProjectDiscovery
References
5github.com
https://github.com/apereo/cas github.com
https://github.com/apereo/cas/commit/376bf087d6d4267f61fc9f8028aa0d1ef407c3f0 github.com
https://github.com/apereo/cas/releases nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-42567