OpenConext/OpenConext-engineblock

OpenConext/OpenConext-engineblock

Releases319
Frequency2 weeks 3 days
Last Release
Stars17
OpenConext SAML 2.0 IdP/SP Gateway

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can result in Allows an attacker to inject arbitrary web scripts or HTML into help and login pages. This attack appear to be exploitable via the victim opening a specially crafted URL.