Ellucian是Ellucian公司的支持 SaaS 的开放和灵活技术生态系统。 Ellucian Ethos Identity 5.10.5 之前版本存在跨站脚本漏洞,该漏洞源于文件 /cas/logout 存在未知函数,通过参数 url 导致跨站脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ellucian | Ethos Identity | 5.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822. | https://github.com/cberman/CVE-2023-2822-demo | POC Details |
| 2 | A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-2822.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet