1 results (0.008 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser. MendixSSO versiones anteriores a 2.1.1 incluyéndola, contiene endpoints que hacen uso del manejador openid, el cual sufre una vulnerabilidad de tipo Cross-Site Scripting por medio de la ruta URL.&#xa0;Esto es causado por el reflejo de los datos suministrados por el usuario sin la codificación de salida o escape HTML apropiado. • https://hackerone.com/reports/838178 https://marketplace.mendix.com/link/component/111349 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •