CyberRota Analysis
AI-GeneratedOpen Access Management (OpenAM) prior to version 16.1.1 is vulnerable due to insufficient encoding of user-supplied parameters in the OAuth 2.0 and OpenID Connect authorization endpoints, allowing unauthenticated attackers to execute scripts in the OpenAM origin through crafted authorization requests. This vulnerability poses a high risk of cross-site scripting (XSS) attacks, potentially compromising user data and session integrity. Organizations using OpenAM should prioritize upgrading to version 16.1.1 to mitigate this security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a crafted authorization request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.