PT-2024-28040 · Syncope+1 · Syncope+2

Published

2024-07-22

·

Updated

2024-12-06

·

CVE-2024-38503

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Syncope versions prior to 3.0.8
Description The issue allows HTML tags to be added to any text field when editing a user, group, or object in the Syncope Console, potentially leading to exploits. The same vulnerability is found in the Syncope Enduser when editing "Personal Information" or "User Requests".
Recommendations For versions prior to 3.0.8, upgrade to version 3.0.8 to fix the issue. As a temporary workaround, consider restricting the ability to add HTML tags to text fields in the Syncope Console and Syncope Enduser until the upgrade is applied.

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-38503
GHSA-8PXV-X6JQ-5VW9

Affected Products

Syncope
Syncope Console
Syncope Enduser