PT-2023-9891 · Unknown · Simplesamlphp+1

Published

2023-01-17

·

Updated

2024-08-07

·

CVE-2010-10008

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions simplesamlphp simplesamlphp-module-openidprovider versions up to 0.8.x
Description A vulnerability was found in the simplesamlphp simplesamlphp-module-openidprovider. The issue affects an unknown functionality of the file templates/trust.tpl.php. The manipulation of the argument StateID leads to cross-site scripting. The attack can be launched remotely.
Recommendations Upgrading to version 0.9.0 is able to address this issue. As a temporary workaround, consider restricting access to the templates/trust.tpl.php file until a patch is available. Avoid using the argument StateID in the affected functionality until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2010-10008
GHSA-CHGC-RQJR-46GG

Affected Products

Simplesamlphp
Simplesamlphp-Module-Openidprovider