S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-2822 Scanner

CVE-2023-2822 scanner - Cross-Site Scripting (XSS) vulnerability in Ethos Identity

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2822
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.10.6 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-229596.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Ethos Identityby Ellucian
5.10.0
Updated Aug 22, 2026View on NVD →
Detail

Ellucian Ethos Identity is a product that offers single sign-on service to various educational institutions. It is designed to make login processes easier and more secure. The software allows students, faculty, and staff to access online applications with just one set of credentials, eliminating the need to remember multiple logins. Ethos Identity also provides a way for institutions to manage and protect user data, ensuring that only authorized personnel can access it.

However, the CVE-2023-2822 vulnerability has been detected in Ethos Identity up to version 5.10.5. This vulnerability allows attackers to inject malicious code into unsuspecting users' browsers, leading to cross-site scripting attacks. By manipulating the URL argument in the /cas/logout file, attackers can steal sensitive information like usernames and passwords, compromising the security of the system and user data stored within it.

If this vulnerability is exploited, the consequences could be severe. Attackers can steal sensitive information, including personal data, banking information, and login credentials. These types of attacks can also compromise the security of the entire system, making it vulnerable to further attacks. This can lead to reputational damage to the educational institution, affecting its credibility and causing a loss of trust among students, faculty, and staff.

At s4e.io, we provide comprehensive vulnerability scanning and management services to help protect your digital assets. Our platform offers advanced features designed to detect and address vulnerabilities quickly, efficiently, and effectively. By using our platform, you can stay informed about the latest threat intelligence and take proactive measures to protect your institution's sensitive data. Don't wait until it's too late - sign up for s4e.io today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Upgrade to version 5.10.6 or higher
  • Stay up to date with security patches and upgrades
  • Implement web application firewalls to detect and block malicious activity
  • Regularly conduct security audits and penetration testing
  • Train employees and users on safe browsing habits and how to identify and report suspicious activities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-2822 scanner - Cross-Site Scripting (XSS) vulnerability in Ethos Identity | S4E