Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this issue to inject client-side scripts into the "select_sso()" function. The payload is triggered when the victim opens a prepared /ux/jss-sso/arslogin?[XSS] link and then clicks the "Login" button.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/149007/BMC-MyIT-Java-System-Solutions-SSO-Plugin-4.0.13.1-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/bugtraq/2018/Aug/41 | Exploit Mailing List Third Party Advisory |
http://packetstormsecurity.com/files/149007/BMC-MyIT-Java-System-Solutions-SSO-Plugin-4.0.13.1-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
http://seclists.org/bugtraq/2018/Aug/41 | Exploit Mailing List Third Party Advisory |
Configurations
History
21 Nov 2024, 03:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/149007/BMC-MyIT-Java-System-Solutions-SSO-Plugin-4.0.13.1-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://seclists.org/bugtraq/2018/Aug/41 - Exploit, Mailing List, Third Party Advisory |
Information
Published : 2018-08-21 16:29
Updated : 2024-11-21 03:51
NVD link : CVE-2018-15528
Mitre link : CVE-2018-15528
CVE.ORG link : CVE-2018-15528
JSON object : View
Products Affected
javasystemsolutions
- sso_plugin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')