PT-2023-9891 · Unknown · Simplesamlphp+1

CVE-2010-10008

·

Publicado

2023-01-17

·

Atualizado

2024-08-07

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions simplesamlphp simplesamlphp-module-openidprovider versions up to 0.8.x
Description A vulnerability was found in the simplesamlphp simplesamlphp-module-openidprovider. The issue affects an unknown functionality of the file templates/trust.tpl.php. The manipulation of the argument StateID leads to cross-site scripting. The attack can be launched remotely.
Recommendations Upgrading to version 0.9.0 is able to address this issue. As a temporary workaround, consider restricting access to the templates/trust.tpl.php file until a patch is available. Avoid using the argument StateID in the affected functionality until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-10008
GHSA-CHGC-RQJR-46GG

Produtos afetados

Simplesamlphp
Simplesamlphp-Module-Openidprovider