PT-2024-28040 · Syncope+1 · Syncope+2
Published
2024-07-22
·
Updated
2024-12-06
·
CVE-2024-38503
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Syncope versions prior to 3.0.8
Description
The issue allows HTML tags to be added to any text field when editing a user, group, or object in the Syncope Console, potentially leading to exploits. The same vulnerability is found in the Syncope Enduser when editing "Personal Information" or "User Requests".
Recommendations
For versions prior to 3.0.8, upgrade to version 3.0.8 to fix the issue. As a temporary workaround, consider restricting the ability to add HTML tags to text fields in the Syncope Console and Syncope Enduser until the upgrade is applied.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Syncope
Syncope Console
Syncope Enduser