Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2021-41174 Vulnerability in npm package @grafana/data
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2018-20676 Vulnerability in maven package org.webjars.npm:bootstrap
CVE-2020-12648 Vulnerability in maven package org.webjars.npm:tinymce
CVE-2022-3510 Vulnerability in maven package com.google.protobuf:protobuf-java