medium · CVSS v3 6.1 · CVSS v4 5.3
CVE-2026-105114
OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to in…
Description
OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.1
- CVSS v4
- 5.3
- EPSS
- —