CVE Database
/

CVE-2018-17184

Back to search

CVE-2018-17184

Published: Nov 6, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

VendorProductVersions

Apache Software Foundation

Apache Syncope

affected
Apache Syncope releases prior to 2.0.11 and 2.1.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now