In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.
References
Configurations
History
24 Apr 2025, 14:53
Type | Values Removed | Values Added |
---|---|---|
First Time |
Veridiumid veridiumad
Veridiumid |
|
CPE | cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:* | |
References | () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - Third Party Advisory | |
References | () https://veridiumid.com/veridium-id-authentication-platform/ - Product |
21 Nov 2024, 08:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - | |
References | () https://veridiumid.com/veridium-id-authentication-platform/ - |
05 Nov 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
03 Apr 2024, 17:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-03 17:15
Updated : 2025-04-24 14:53
NVD link : CVE-2023-44040
Mitre link : CVE-2023-44040
CVE.ORG link : CVE-2023-44040
JSON object : View
Products Affected
veridiumid
- veridiumad
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')