CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. See the original NVD description below for full technical details.
CVE
CVE-2019-3872
Severity
MEDIUM
CVSS
5.4
EPSS
0.70%
Original NVD Description
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)