PT-2023-14571 · WordPress · Saml Sso Premium Multisite Wordpress Plugin+2

Chirag Ketan Prajapati

+1

·

Published

2023-01-30

·

Updated

2025-03-28

·

CVE-2022-4496

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAML SSO Standard WordPress plugin versions 16.0.0 through 16.0.7 SAML SSO Premium WordPress plugin versions 12.0.0 through 12.0.x before 12.1.0 SAML SSO Premium Multisite WordPress plugin versions 20.0.0 through 20.0.6
Description The issue arises from the failure to validate that the redirect parameter to the SSO login endpoint points to an internal site URL, leading to an Open Redirect issue when the user is already logged in.
Recommendations For SAML SSO Standard WordPress plugin versions 16.0.0 through 16.0.7, update to version 16.0.8 or later. For SAML SSO Premium WordPress plugin versions 12.0.0 through 12.0.x before 12.1.0, update to version 12.1.0 or later. For SAML SSO Premium Multisite WordPress plugin versions 20.0.0 through 20.0.6, update to version 20.0.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-4496

Affected Products

Saml Sso Premium Multisite Wordpress Plugin
Saml Sso Premium Wordpress Plugin
Saml Sso Standard Wordpress Plugin