|
Jasig phpCAS 1.0.0, 1.0.1, and 1.1.0 contain a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate a URL containing a bogus ticket upon submission, prior to displaying it within the error page. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|