Limited Black Friday Offer:
Security for everyone

Ellucian Ethos Identity CAS - Cross-Site Scripting CVE-2023-2822 Scanner

Remote attacker can perform a reflected cross site scripting attack (XSS) by injecting malicious payload.

SCAN NOW

Short Info


Level

Medium

Type

Single Scan

Can be used by

Asset Owner

Estimated Time

10 sec

Scan only one

Url

Parent Category

Ellucian Ethos Identity CAS - Cross-Site Scripting CVE-2023-2822 Scanner Detail

A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.10.6 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-229596.