PT-2020-7857 · Ipsilon · Ipsilon

Michael Scherer

·

Published

2020-02-17

·

Updated

2024-08-06

·

CVE-2015-5216

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Ipsilon versions 0.1.0 through 1.0.0
Description: The issue arises from the Identity Provider (IdP) server not properly escaping certain characters in a Python exception-message template. This makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.
Recommendations: For Ipsilon versions 0.1.0 through 1.0.0, update to version 1.0.1 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2015-5216

Affected Products

Ipsilon