CVE-2024-38503
published 2024-07-22CVE-2024-38503: When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.70%
48.9th percentile
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.
The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”.
Users are recommended to upgrade to version 3.0.8, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | syncope | 2.1.0 – 2.1.14 | — |
| apache | syncope | >= 3.0.0 < 3.0.8 | 3.0.8 |
| apache_software_foundation | apache_syncope | 2.1 – 2.1.14 | — |
| apache_software_foundation | apache_syncope | 3.0 – 3.0.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Syncope Improper Input Validation vulnerability
osv·2024-07-22
CVE-2024-38503 [HIGH] Apache Syncope Improper Input Validation vulnerability
Apache Syncope Improper Input Validation vulnerability
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.
The same vulnerability was found in the Syncope Enduser, when editing "Personal Information" or "User Requests".
Users are recommended to upgrade to version 3.0.8, which fixes this issue.
GHSA
Apache Syncope Improper Input Validation vulnerability
ghsa·2024-07-22
CVE-2024-38503 [HIGH] CWE-20 Apache Syncope Improper Input Validation vulnerability
Apache Syncope Improper Input Validation vulnerability
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits.
The same vulnerability was found in the Syncope Enduser, when editing "Personal Information" or "User Requests".
Users are recommended to upgrade to version 3.0.8, which fixes this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduserhttps://www.openwall.com/lists/oss-security/2024/07/22/3http://www.openwall.com/lists/oss-security/2024/07/22/3https://syncope.apache.org/security#cve-2024-38503-html-tags-can-be-injected-into-console-or-enduser
2024-07-22
Published