Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
| Software | From | Fixed in |
|---|---|---|
| apereo / central_authentication_service | 6.3.0 | 6.3.7.1 |
| apereo / central_authentication_service | 6.4.0 | 6.4.2 |
org.apereo.cas / cas-server-core-web
|
- | 6.4.2 |