Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2021-23327 Vulnerability in maven package org.webjars.npm:apexcharts
CVE-2021-29300 Vulnerability in npm package opened
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2018-20594 Vulnerability in maven package org.hswebframework.web:hsweb-system-workflow-local