PT-2023-9891 · Unknown · Simplesamlphp+1
CVE-2010-10008
·
Publicado
2023-01-17
·
Atualizado
2024-08-07
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
simplesamlphp simplesamlphp-module-openidprovider versions up to 0.8.x
Description
A vulnerability was found in the simplesamlphp simplesamlphp-module-openidprovider. The issue affects an unknown functionality of the file templates/trust.tpl.php. The manipulation of the argument
StateID leads to cross-site scripting. The attack can be launched remotely.Recommendations
Upgrading to version 0.9.0 is able to address this issue.
As a temporary workaround, consider restricting access to the
templates/trust.tpl.php file until a patch is available.
Avoid using the argument StateID in the affected functionality until the issue is resolved.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simplesamlphp
Simplesamlphp-Module-Openidprovider