CVE-2020-5301
- EPSS 0.14%
- Veröffentlicht 21.04.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:33:52
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending with `.php` and process those as...
CVE-2020-5226
- EPSS 0.4%
- Veröffentlicht 24.01.2020 22:15:23
- Zuletzt bearbeitet 21.11.2024 05:33:43
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduce...
CVE-2020-5225
- EPSS 0.32%
- Veröffentlicht 24.01.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:42
Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not properly sanitize the report identifier obtained from the request. This al...
CVE-2019-3465
- EPSS 3.05%
- Veröffentlicht 07.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:42:06
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by...
CVE-2011-4625
- EPSS 0.27%
- Veröffentlicht 06.11.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:32:41
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
CVE-2018-7711
- EPSS 0.21%
- Veröffentlicht 05.03.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:34
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation...
CVE-2018-7644
- EPSS 0.07%
- Veröffentlicht 05.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:28
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass ...
CVE-2017-18122
- EPSS 0.31%
- Veröffentlicht 02.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:23
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signatur...
CVE-2017-18121
- EPSS 0.36%
- Veröffentlicht 02.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:23
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.
CVE-2018-6521
- EPSS 0.59%
- Veröffentlicht 02.02.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:49
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions...