Back to search
CVE-2020-5497
Published: Jan 4, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20200227 CVE-2020-5497 - MITREid Connect XSS
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now