PT-2023-9886 · Unknown · Simplesamlphp+1

Published

2023-01-01

·

Updated

2024-08-07

·

CVE-2010-10002

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SimpleSAMLphp simplesamlphp-module-openid versions prior to 1.0
Description A vulnerability has been found in the OpenID Handler component of SimpleSAMLphp simplesamlphp-module-openid. The issue affects an unknown function of the file templates/consumer.php. The manipulation of the AuthState argument leads to cross-site scripting. It is possible to launch the attack remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult.
Recommendations For versions prior to 1.0, upgrade to version 1.0 to address this issue. As a temporary workaround, consider restricting access to the OpenID Handler component until the upgrade is applied. Avoid using the AuthState argument in the affected component until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2010-10002
GHSA-GGJ9-6X8J-49W9

Affected Products

Simplesamlphp
Simplesamlphp-Module-Openid