logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-5497

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-5497

Description:
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.
Last updated date:
01/24/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/20/2020
Reference url to background

https://github.com/mitreid-connect/OpenID-Connect-Java-Spring-Server/issues/1521

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/24/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/24/2023
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy