Description
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.
Remediation
References
http://syncope.apache.org/security
Related Vulnerabilities
CVE-2023-29521 Vulnerability in maven package org.xwiki.platform:xwiki-platform-vfs-ui
CVE-2021-21611 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1000150 Vulnerability in maven package org.jenkins-ci.plugins:reverse-proxy-auth-plugin
CVE-2021-41182 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2022-37865 Vulnerability in maven package org.apache.ivy:ivy