In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.
References
Configurations
History
24 Apr 2025, 14:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - Third Party Advisory | |
References | () https://veridiumid.com/veridium-id-authentication-platform/ - Product | |
First Time |
Veridiumid veridiumad
Veridiumid |
|
CPE | cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:* |
Information
Published : 2024-04-03 17:15
Updated : 2025-04-24 14:53
NVD link : CVE-2023-44040
Mitre link : CVE-2023-44040
CVE.ORG link : CVE-2023-44040
JSON object : View
Products Affected
veridiumid
- veridiumad
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')