Impact
Apache Syncope is vulnerable to an unauthenticated reflected XSS flaw that can be triggered by crafting a URL to the Console or Enduser login pages. The application fails to neutralize special characters, allowing an attacker to inject HTML tags and inline JavaScript. When an end‑user visits the malicious URL, the attacker can steal session cookies, deface the site, or execute other client‑side compromise actions.
Affected Systems
Affected versions are 4.0.4 through 4.0.7 and 4.1.0‑M0 through 4.1.2 of Apache Syncope. The flaw exists in the login pages of both the Console and Enduser interfaces.
Risk and Exploitability
The vulnerability allows an attacker to inject custom HTML and JavaScript into the login pages of both the Console and Enduser interfaces by crafting a malicious URL. No authentication is required for the attacker to exploit this flaw. The embedded script can execute in the victim's browser, potentially allowing a third party to acquire session cookies, manipulate the page, or perform other client‑side actions. The EPSS score of <1% indicates that attacks leveraging this weakness are currently unlikely, but the CVSS score of 6.1 reflects a medium severity. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment