Description
Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
Remediation
References
https://apereo.github.io/2021/10/18/restvuln/
https://github.com/apereo/cas/releases
Related Vulnerabilities
CVE-2015-0899 Vulnerability in maven package struts:struts
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-manager
CVE-2021-23348 Vulnerability in npm package portprocesses
CVE-2020-6464 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-32809 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4