PT-2023-14571 · WordPress · Saml Sso Premium Multisite Wordpress Plugin+2

Chirag Ketan Prajapati

+1

·

Publicado

2023-01-30

·

Atualizado

2025-03-28

·

CVE-2022-4496

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAML SSO Standard WordPress plugin versions 16.0.0 through 16.0.7 SAML SSO Premium WordPress plugin versions 12.0.0 through 12.0.x before 12.1.0 SAML SSO Premium Multisite WordPress plugin versions 20.0.0 through 20.0.6
Description The issue arises from the failure to validate that the redirect parameter to the SSO login endpoint points to an internal site URL, leading to an Open Redirect issue when the user is already logged in.
Recommendations For SAML SSO Standard WordPress plugin versions 16.0.0 through 16.0.7, update to version 16.0.8 or later. For SAML SSO Premium WordPress plugin versions 12.0.0 through 12.0.x before 12.1.0, update to version 12.1.0 or later. For SAML SSO Premium Multisite WordPress plugin versions 20.0.0 through 20.0.6, update to version 20.0.7 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2022-4496

Produtos afetados

Saml Sso Premium Multisite Wordpress Plugin
Saml Sso Premium Wordpress Plugin
Saml Sso Standard Wordpress Plugin