Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-38503


When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.


Published

2024-07-22T10:15:08.723

Last Modified

2024-12-06T22:15:19.420

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache syncope ≤ 2.1.14 Yes
Application apache syncope < 3.0.8 Yes

References