PT-2023-14571 · WordPress · Saml Sso Premium Multisite Wordpress Plugin+2
Chirag Ketan Prajapati
+1
·
Published
2023-01-30
·
Updated
2025-03-28
·
CVE-2022-4496
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAML SSO Standard WordPress plugin versions 16.0.0 through 16.0.7
SAML SSO Premium WordPress plugin versions 12.0.0 through 12.0.x before 12.1.0
SAML SSO Premium Multisite WordPress plugin versions 20.0.0 through 20.0.6
Description
The issue arises from the failure to validate that the redirect parameter to the SSO login endpoint points to an internal site URL, leading to an Open Redirect issue when the user is already logged in.
Recommendations
For SAML SSO Standard WordPress plugin versions 16.0.0 through 16.0.7, update to version 16.0.8 or later.
For SAML SSO Premium WordPress plugin versions 12.0.0 through 12.0.x before 12.1.0, update to version 12.1.0 or later.
For SAML SSO Premium Multisite WordPress plugin versions 20.0.0 through 20.0.6, update to version 20.0.7 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Saml Sso Premium Multisite Wordpress Plugin
Saml Sso Premium Wordpress Plugin
Saml Sso Standard Wordpress Plugin