Back

CVE-2014-4172

CRITICAL

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

Published: Jan 24, 2020 Modified: Jun 17, 2026
CWE-74

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (5)

Vendor Product Version
apereo .net_cas_client * < 1.0.2
apereo java_cas_client * < 3.3.2
apereo phpcas * < 1.3.3
debian debian_linux 7.0
fedoraproject fedora 20

GitHub Security Advisory GHSA-9fc5-q25c-r2wr

Jasig Java CAS Client, .NET CAS Client, and phpCAS contain URL parameter injection vulnerability

nuget DotNetCasClient < 1.0.2 Fixed: 1.0.2
maven org.jasig.cas:cas-client < 3.3.2 Fixed: 3.3.2
composer jasig/phpcas < 1.3.3 Fixed: 1.3.3

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.06%

Top 7% most likely to be exploited

Threat Score 41 / 100

Data Sources

NVD EPSS GitHub