Record summary

CVE-2021-42567 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

org.apereo.cas:cas-server-core-web

Browse Maven / org.apereo.cas:cas-server-core-web
GitHub AdvisoryBefore 6.4.2 · Fixed in 6.4.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMApereo CAS Cross-Site ScriptingCVSS 6.1

Apereo CAS through 6.4.1 allows cross-site scripting via POST requests sent to the REST API endpoints.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a victim's browser, potentially leading to session hijacking, data theft, or defacement.

Remediation

Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.

WeaknessesCWE-79
Authorspdteam
Template tagscve2021cveapereoxsscasvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apereo:central_authentication_service:*:*:*:*:*:*:*:*
Shodan: http.title:'CAS - Central Authentication Service'
Shodan: http.title:'cas - central authentication service'
FOFA: title='cas - central authentication service'
Google: intitle:'cas - central authentication service'

Source: ProjectDiscovery

References

5