Severity: moderate 

Affected versions:

- Apache Syncope 
(org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui) 4.0.4 
through 4.0.7
- Apache Syncope 
(org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui) 4.1.0-M0 
through 4.1.2

Description:

Improper neutralization of input during web page generation ('cross-site 
scripting') vulnerability in Apache Syncope.



The notification message, as optionally shown by Console's and Enduser's login 
pages can be instructed to display HTML tags with unsafe JS inline, via 
malicious HTTP link generation.



This issue affects Apache Syncope: from 4.0.4 through 4.0.7, from 4.1.0-M0 
through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Credit:

Alon Galili (finder)

References:

https://syncope.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-78318

Reply via email to