First published: Fri Jul 19 2019(Updated: )
ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Openidc Mod Auth Openidc | <2.3.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-1010247.
The severity level of CVE-2019-1010247 is medium with a CVSS score of 6.1.
The impact of CVE-2019-1010247 is redirecting the user to a phishing page or interacting with the application on behalf of the user.
The affected component of CVE-2019-1010247 is the file src/mod_auth_openidc.c on line 3109.
To fix CVE-2019-1010247, upgrade to version 2.3.10.2 of ZmartZone IAM mod_auth_openidc.