CVE-2017-7591
EUVD-2017-1659609.04.2017, 01:59
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openidm_project | openidm | 𝑥 ≤ 4.0.0 |
| openidm_project | openidm | 4.5.0 |
𝑥
= Vulnerable software versions
References