Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Marvin Addison

#24934of 53,634
9.8Total CVSS
Vulnerabilities · 1
PT-2020-7671
9.8
2014-09-24
Jasig · Jasig Java Cas Client · CVE-2014-4172
**Name of the Vulnerable Software and Affected Versions** Jasig Java CAS Client versions prior to 3.3.2 .NET CAS Client versions prior to 1.0.2 phpCAS versions prior to 1.3.3 **Description** A URL parameter injection issue was found in the CAS protocol, specifically in the back-channel ticket validation step. This allows remote attackers to inject arbitrary web script or HTML via the `service` parameter to `validation/AbstractUrlBasedTicketValidator.java` or the `pgtUrl` parameter to `validation/Cas20ServiceTicketValidator.java`. **Recommendations** For Jasig Java CAS Client versions prior to 3.3.2, update to version 3.3.2 or later. For .NET CAS Client versions prior to 1.0.2, update to version 1.0.2 or later. For phpCAS versions prior to 1.3.3, update to version 1.3.3 or later.