CVE-2017-7591
09.04.2017, 01:59
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.
Vendor | Product | Version |
---|---|---|
openidm_project | openidm | 𝑥 ≤ 4.0.0 |
openidm_project | openidm | 4.5.0 |
𝑥
= Vulnerable software versions
References