PT-2023-9886 · Unknown · Simplesamlphp+1
Published
2023-01-01
·
Updated
2024-08-07
·
CVE-2010-10002
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SimpleSAMLphp simplesamlphp-module-openid versions prior to 1.0
Description
A vulnerability has been found in the OpenID Handler component of SimpleSAMLphp simplesamlphp-module-openid. The issue affects an unknown function of the file templates/consumer.php. The manipulation of the
AuthState argument leads to cross-site scripting. It is possible to launch the attack remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult.Recommendations
For versions prior to 1.0, upgrade to version 1.0 to address this issue. As a temporary workaround, consider restricting access to the
OpenID Handler component until the upgrade is applied. Avoid using the AuthState argument in the affected component until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplesamlphp
Simplesamlphp-Module-Openid