In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.
CVSS
No CVSS.
References
Configurations
History
24 Apr 2025, 14:53
Type | Values Removed | Values Added |
---|---|---|
First Time |
Veridiumid veridiumad
Veridiumid |
|
CPE | cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:* | |
References | () https://veridiumid.com/veridium-id-authentication-platform/ - Product | |
References | () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - Third Party Advisory |
03 Apr 2024, 17:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-03 17:15
Updated : 2025-04-24 14:53
NVD link : CVE-2023-44040
Mitre link : CVE-2023-44040
JSON object : View
Products Affected
veridiumid
- veridiumad
CWE
No CWE.