Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2021-22112 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2023-46298 Vulnerability in npm package next
CVE-2021-21380 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ratings-api
CVE-2021-26539 Vulnerability in npm package sanitize-html
CVE-2020-28281 Vulnerability in npm package set-object-value