{"id":"GHSA-6qj8-c27w-rp33","summary":"Cross-site scripting in Apache Syncome EndUser","details":"It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.","aliases":["CVE-2019-17557"],"modified":"2023-11-08T04:01:24.189008Z","published":"2022-01-06T19:38:07Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2021-05-25T20:49:00Z","nvd_published_at":"2020-05-04T13:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17557"},{"type":"WEB","url":"http://syncope.apache.org/security"}],"affected":[{"package":{"name":"org.apache.syncope.client:syncope-client-enduser","ecosystem":"Maven","purl":"pkg:maven/org.apache.syncope.client/syncope-client-enduser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.15"}]}],"versions":["2.0.0","2.0.0-M1","2.0.0-M2","2.0.0-M3","2.0.0-M4","2.0.0.M5","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-6qj8-c27w-rp33/GHSA-6qj8-c27w-rp33.json"}},{"package":{"name":"org.apache.syncope.client:syncope-client-enduser","ecosystem":"Maven","purl":"pkg:maven/org.apache.syncope.client/syncope-client-enduser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.6"}]}],"versions":["2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-6qj8-c27w-rp33/GHSA-6qj8-c27w-rp33.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}