4.3
CVSSv2

CVE-2014-7293

Published: 02/01/2015 Updated: 05/01/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the logon page in NYU OpenSSO Integration 2.1 and previous versions for Ex Libris Patron Directory Services (PDS) allows remote malicious users to inject arbitrary web script or HTML via the url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

nyu opensso integration

Exploits

Ex Libris Patron Directory Services version 21 suffers from a cross site scripting vulnerability ...