CVE-2023-44040

In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.
Configurations

Configuration 1 (hide)

cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:*

History

24 Apr 2025, 14:53

Type Values Removed Values Added
First Time Veridiumid veridiumad
Veridiumid
CPE cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:*
References () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - Third Party Advisory
References () https://veridiumid.com/veridium-id-authentication-platform/ - () https://veridiumid.com/veridium-id-authentication-platform/ - Product

21 Nov 2024, 08:25

Type Values Removed Values Added
References () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement -
References () https://veridiumid.com/veridium-id-authentication-platform/ - () https://veridiumid.com/veridium-id-authentication-platform/ -

05 Nov 2024, 15:35

Type Values Removed Values Added
Summary
  • (es) En VeridiumID anterior a 3.5.0, la página del proveedor de identidad es susceptible a una vulnerabilidad de Cross Site Scripting (XSS) que puede ser explotada por un atacante interno no autenticado para la ejecución de JavaScript en el contexto del usuario que intenta autenticarse.
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

03 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 17:15

Updated : 2025-04-24 14:53


NVD link : CVE-2023-44040

Mitre link : CVE-2023-44040

CVE.ORG link : CVE-2023-44040


JSON object : View

Products Affected

veridiumid

  • veridiumad
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')