Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2022-0764 Vulnerability in npm package strapi
CVE-2022-0672 Vulnerability in maven package org.eclipse.lemminx:lemminx-parent
CVE-2021-4245 Vulnerability in npm package rfc6902
CVE-2022-4725 Vulnerability in maven package com.amazonaws:aws-android-sdk-core
CVE-2021-41165 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4