Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2022-25231 Vulnerability in npm package node-opcua
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2009-2901 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2023-23850 Vulnerability in maven package org.jenkins-ci.plugins:synopsys-coverity
CVE-2023-40350 Vulnerability in maven package org.jenkins-ci.plugins:docker-swarm