Apache Syncope: HTML tags can be injected into Console or Enduser text fields
Vulnerability Description
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-38503
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Basalt IT-Security Team
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →