imPC@ndo IT

Tracker / CVE-2018-17184

CVE-2018-17184

Medium 5.4

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

Affected products and versions

apache syncope · 2.0.0 → 2.0.11
apache syncope · 2.1.0 → 2.1.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References