rootpwn

medium · CVSS v3 6.1 · CVSS v4 5.3

CVE-2026-105114

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to in…

Description

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
5.3
EPSS
—

← All CVEs