Reflected Cross Site Scripting (XSS) in Devise Token Auth's omniauth failure endpoint

Reflected Cross Site Scripting (XSS) in Devise Token Auth's omniauth failure endpoint

CVE-2019-16751 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller.

Learn more about our Web Application Penetration Testing UK.