CVE-2023-41873
- EPSS 0.15%
- Veröffentlicht 13.12.2024 15:15:25
- Zuletzt bearbeitet 13.12.2024 15:15:25
Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through 5.0.4.
CVE-2022-4496
- EPSS 0.26%
- Veröffentlicht 30.01.2023 21:15:10
- Zuletzt bearbeitet 28.03.2025 14:15:18
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect param...
CVE-2020-6850
- EPSS 0.36%
- Veröffentlicht 17.02.2020 16:15:28
- Zuletzt bearbeitet 21.11.2024 05:36:17
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the s...
CVE-2019-12346
- EPSS 0.14%
- Veröffentlicht 24.06.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:22:38
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.