cbcvebase.
CVE-2018-17184
published 2018-11-06

CVE-2018-17184: A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names…

PriorityP424medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.19%
64.4th percentile
A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

Affected

3 ranges
VendorProductVersion rangeFixed in
apachesyncope>= 2.0.0 < 2.0.112.0.11
apachesyncope>= 2.1.0 < 2.1.22.1.2
apache_software_foundationapache_syncope

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.