Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Marvin Addison

#27575of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2020-7671
9.8
2014-09-24
Jasig · Jasig Java Cas Client · CVE-2014-4172
**Name of the Vulnerable Software and Affected Versions** Jasig Java CAS Client versions prior to 3.3.2 .NET CAS Client versions prior to 1.0.2 phpCAS versions prior to 1.3.3 **Description** A URL parameter injection issue was found in the CAS protocol, specifically in the back-channel ticket validation step. This allows remote attackers to inject arbitrary web script or HTML via the `service` parameter to `validation/AbstractUrlBasedTicketValidator.java` or the `pgtUrl` parameter to `validation/Cas20ServiceTicketValidator.java`. **Recommendations** For Jasig Java CAS Client versions prior to 3.3.2, update to version 3.3.2 or later. For .NET CAS Client versions prior to 1.0.2, update to version 1.0.2 or later. For phpCAS versions prior to 1.3.3, update to version 1.3.3 or later.