QID 12507
Date Published: 2021-06-16
QID 12507: SimpleSAMLphp Cross-Site Scripting Vulnerability(202001-01)
SimpleSAMLphp is an award-winning application written in native PHP that deals with authentication.
Affected Versions:
SimpleSAMLphp 1.18.0 - 1.18.3
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of SimpleSAMLphp
An attacker may take advantage of this issue to manually craft a modified email sent via the error reporting mechanism, such as this email might trick a system administrator into performing an action, such as introducing their credentials into a phishing web site that resembles the original.
Solution
Customers are advised upgrade to the SimpleSAMLphp installation to version 1.18.4 or latest one.
Vendor References
- 202001-01 -
simplesamlphp.org/security/202001-01
CVEs related to QID 12507
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 202001-01 |
|