Trustwave SpiderLabs Security Advisory TWSL2024-002: Multiple Cross-Site Scripting Vulnerabilities in The OptimalCloud IAM Platform Published: 07/12/2024 Version: 1.0 Vendor: Optimalidm (https://optimalidm.com/) Product: The OptimalCloud Version affected: N/A Product description: The OptimalCloud from Optimal IdM is a scalable and affordable Identity and Access Management (IAM) solution built for the security and usability needs of small, mid-sized and enterprise organizations. Finding 1: Persistent Cross-Site Scripting (DOM based) *****Credit: Jean Calvin Mugabo of Trustwave CWE: CWE-79 - Vulnerability Overview: The feature for adding Multi-factor Authentication (MFA) devices is vulnerable to Cross-Site Scripting (XSS). - Location of Vulnerability: - Path: Home Portal > Account Settings > Multi-Factor Token/Device Options > MFA Device/Token Management > Add Token/Device. - Description: The form at the specified location does not properly validate user inputs, allowing the submission of JavaScript code. - Evidence of Vulnerability: - Details: Spiderlabs added an MFA device containing the following JavaScript code: `