Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2022-45394 Vulnerability in maven package org.jenkins-ci.plugins:delete-log-plugin
CVE-2021-23369 Vulnerability in npm package handlebars
CVE-2022-2932 Vulnerability in npm package mobiledoc-dom-renderer
CVE-2022-31112 Vulnerability in npm package parse-server
CVE-2022-41935 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui