Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2021-3810 Vulnerability in npm package code-server
CVE-2015-0250 Vulnerability in maven package batik:batik-transcoder
CVE-2021-24033 Vulnerability in npm package react-dev-utils
CVE-2022-29648 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2019-16763 Vulnerability in maven package org.webjars.npm:pannellum