Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when proxy mode is enabled, allows remote attackers to inject arbitrary web script or HTML via a callback URL.
- https://issues.jasig.org/browse/PHPCAS-67
- https://wiki.jasig.org/display/CASC/phpCAS+ChangeLog
No PoCs found on GitHub currently.