Loading
It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.
Use CWE-79, Dogtagpki vendor hub and Dogtagpki product page to widen CVE-2019-10178 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-20179, CVE-2021-3551 and CVE-2022-2414 for nearby disclosures in the same product family.