CyberRota Analysis
AI-GeneratedThe Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) due to inadequate HTML encoding in the admin panel's search results and updater logs. This flaw allows authenticated users with the ability to modify directory attributes, or low-privileged local users, to inject malicious scripts that execute in the browser of administrators viewing the affected content. Organizations using this connector should prioritize remediation to protect against potential exploitation that could compromise sensitive administrative sessions.
Original NVD Description
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search results or update logs.