Yamcs < 5.9.4 contains a stored XSS caused by inadequate HTML escaping of attacker-controlled redirect_uri parameter in authorization template, letting attackers execute JavaScript to steal authentication data, exploit requires user to open crafted URL.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view