漏洞描述
A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
medium.comhttps://medium.com/@cyberninja717/685bb1675dfb↗medium.comhttps://medium.com/@cyberninja717/reflected-cross-site-scripting-vulnerability-in-ellucian-ethos-identity-cas-logout-page-685bb1675dfb↗vuldb.comhttps://vuldb.com/?ctiid.229596↗vuldb.comhttps://vuldb.com/?id.229596↗github.comhttps://github.com/cberman/CVE-2023-2822-demo↗