Description
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.
Remediation
References
http://syncope.apache.org/security
Related Vulnerabilities
CVE-2019-10353 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10430 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner
CVE-2016-3674 Vulnerability in maven package org.jbehave:jbehave-core
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2010-1330 Vulnerability in maven package org.jruby:jruby