Description
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0)
XWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-32729)
IBM WebSEAL Insufficiently Protected Credentials Vulnerability (CVE-2021-20439)
WordPress Plugin Google +1 by BestWebSoft Cross-Site Scripting (1.3.3)