ZeroHour

CVE-2023-44040

CVSS 3.1
6.1 medium
EPSS
<1%p38
Published
()
Modified
Description

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.

Vendors
veridiumid
Products
veridiumad
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.