Записи simplesamlphp
35 опубликованных записей вендора simplesamlphp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 97,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-347 Improper Verification of Cryptographic Signature4
- CWE-20 Improper Input Validation3
- CWE-384 Session Fixation2
- CWE-345 Insufficient Verification of Data Authenticity2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
35 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-6521Эксплойта нет | The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte charsimplesamlphp · simplesamlphp | Критическая9,8 | — | 3,1 % | 1 февр. 2018 г. |
40В плане | CVE-2017-12868Эксплойта нет | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attasimplesamlphp · simplesamlphp · CWE-384 | Критическая9,8 | — | 2,1 % | 1 сент. 2017 г. |
39Наблюдать | CVE-2017-12873Эксплойта нет | SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified othsimplesamlphp · simplesamlphp · CWE-384 | Критическая9,8 | — | 1,7 % | 1 сент. 2017 г. |
37Наблюдать | CVE-2016-9814Эксплойта нет | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x bsimplesamlphp · simplesamlphp · CWE-399 | Критическая9,1 | — | 2,4 % | 16 февр. 2017 г. |
36Наблюдать | CVE-2019-3465Эксплойта нет | Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographicsimplesamlphp · simplesamlphp · CWE-347 | Высокая8,8 | — | 3,0 % | 7 нояб. 2019 г. |
35Наблюдать | CVE-2024-52596Эксплойта нет | SimpleSAMLphp xml-common XXE vulnerabilitysimplesamlphp · xml-common · CWE-611 | Высокая8,8 | — | 1,0 % | 2 дек. 2024 г. |
33Наблюдать | CVE-2024-52806Proof of concept | SimpleSAMLphp SAML2 has an XXE in parsing SAML messagessimplesamlphp · saml2 · CWE-611 | Высокая8,3 | — | 0,4 % | 2 дек. 2024 г. |
32Наблюдать | CVE-2018-7711Эксплойта нет | HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utisimplesamlphp · simplesamlphp · CWE-347 | Высокая8,1 | — | 1,2 % | 5 мар. 2018 г. |
32Наблюдать | CVE-2017-18122Эксплойта нет | A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16.simplesamlphp · simplesamlphp · CWE-347 | Высокая8,1 | — | 1,1 % | 2 февр. 2018 г. |
32Наблюдать | CVE-2026-32600Эксплойта нет | xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryptionsimplesamlphp · xml-security · CWE-354 | Высокая8,2 | — | 0,2 % | 16 мар. 2026 г. |
31Наблюдать | CVE-2017-12869Эксплойта нет | The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an asimplesamlphp · simplesamlphp · CWE-20 | Высокая7,5 | — | 2,4 % | 1 сент. 2017 г. |
31Наблюдать | CVE-2018-6519Эксплойта нет | The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerabsimplesamlphp · saml2 · CWE-74 | Высокая7,5 | — | 1,7 % | 1 февр. 2018 г. |
30Наблюдать | CVE-2017-12874Эксплойта нет | The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signatsimplesamlphp · infocard module · CWE-20 | Высокая7,5 | — | 1,3 % | 1 сент. 2017 г. |
30Наблюдать | CVE-2018-7644Эксплойта нет | The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowsimplesamlphp · simplesamlphp · CWE-347 | Высокая7,5 | — | 1,2 % | 5 мар. 2018 г. |
30Наблюдать | CVE-2011-4625Эксплойта нет | simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decryptsimplesamlphp · simplesamlphp · CWE-755 | Высокая7,5 | — | 0,7 % | 6 нояб. 2019 г. |
30Наблюдать | CVE-2023-49087Эксплойта нет | Validation of SignedInfosimplesamlphp · saml2 · CWE-345 | Высокая7,5 | — | 0,2 % | 30 нояб. 2023 г. |
28Наблюдать | CVE-2026-49284Эксплойта нет | SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmatiosimplesamlphp · simplesamlphp · CWE-345 | Высокая7,1 | — | 0,2 % | 17 июл. 2026 г. |
25Наблюдать | CVE-2016-9955Эксплойта нет | The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 resimplesamlphp · simplesamlphp · CWE-20 | Средняя6,3 | — | 1,2 % | 16 февр. 2017 г. |
24Наблюдать | CVE-2017-18121Эксплойта нет | The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft linkssimplesamlphp · simplesamlphp · CWE-79 | Средняя6,1 | — | 1,2 % | 2 февр. 2018 г. |
24Наблюдать | CVE-2018-6520Эксплойта нет | SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.simplesamlphp · simplesamlphp · CWE-601 | Средняя6,1 | — | 0,9 % | 1 февр. 2018 г. |
24Наблюдать | CVE-2010-10002Эксплойта нет | SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scriptingsimplesamlphp · simplesamlphp-module-openid · CWE-79 | Средняя6,1 | — | 0,6 % | 1 янв. 2023 г. |
24Наблюдать | CVE-2010-10004Эксплойта нет | Information Cards Module cross site scriptingsimplesamlphp · information cards module · CWE-79 | Средняя6,1 | — | 0,5 % | 9 янв. 2023 г. |
24Наблюдать | CVE-2025-65954Эксплойта нет | SimpleSAMLphp-casserver has an Open Redirect vulnerability via logoutsimplesamlphp · simplesamlphp-module-casserver · CWE-601 | Средняя6,1 | — | 0,3 % | 18 мая 2026 г. |
23Наблюдать | CVE-2017-12872Эксплойта нет | The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow rsimplesamlphp · simplesamlphp · CWE-200 | Средняя5,9 | — | 1,5 % | 1 сент. 2017 г. |
23Наблюдать | CVE-2017-12867Эксплойта нет | The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend itssimplesamlphp · simplesamlphp · CWE-613 | Средняя5,9 | — | 1,3 % | 29 авг. 2017 г. |
- CVE-2018-652140В плане
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte char
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %simplesamlphp · simplesamlphp1 февр. 2018 г.
- CVE-2017-1286840В плане
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %simplesamlphp · simplesamlphp1 сент. 2017 г.
- CVE-2017-1287339Наблюдать
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %simplesamlphp · simplesamlphp1 сент. 2017 г.
- CVE-2016-981437Наблюдать
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x b
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %simplesamlphp · simplesamlphp16 февр. 2017 г.
- CVE-2019-346536Наблюдать
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %simplesamlphp · simplesamlphp7 нояб. 2019 г.
- CVE-2024-5259635Наблюдать
SimpleSAMLphp xml-common XXE vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %simplesamlphp · xml-common2 дек. 2024 г.
- CVE-2024-5280633Наблюдать
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
ВысокаяCVSS 8,3Proof of conceptEPSS 0 %simplesamlphp · saml22 дек. 2024 г.
- CVE-2018-771132Наблюдать
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation uti
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp5 мар. 2018 г.
- CVE-2017-1812232Наблюдать
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp2 февр. 2018 г.
- CVE-2026-3260032Наблюдать
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %simplesamlphp · xml-security16 мар. 2026 г.
- CVE-2017-1286931Наблюдать
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simplesamlphp · simplesamlphp1 сент. 2017 г.
- CVE-2018-651931Наблюдать
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerab
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %simplesamlphp · saml21 февр. 2018 г.
- CVE-2017-1287430Наблюдать
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signat
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %simplesamlphp · infocard module1 сент. 2017 г.
- CVE-2018-764430Наблюдать
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allow
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp5 мар. 2018 г.
- CVE-2011-462530Наблюдать
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp6 нояб. 2019 г.
- CVE-2023-4908730Наблюдать
Validation of SignedInfo
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %simplesamlphp · saml230 нояб. 2023 г.
- CVE-2026-4928428Наблюдать
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmatio
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %simplesamlphp · simplesamlphp17 июл. 2026 г.
- CVE-2016-995525Наблюдать
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 re
СредняяCVSS 6,3Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp16 февр. 2017 г.
- CVE-2017-1812124Наблюдать
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links
СредняяCVSS 6,1Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp2 февр. 2018 г.
- CVE-2018-652024Наблюдать
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp1 февр. 2018 г.
- CVE-2010-1000224Наблюдать
SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp-module-openid1 янв. 2023 г.
- CVE-2010-1000424Наблюдать
Information Cards Module cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %simplesamlphp · information cards module9 янв. 2023 г.
- CVE-2025-6595424Наблюдать
SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout
СредняяCVSS 6,1Эксплойта нетEPSS 0 %simplesamlphp · simplesamlphp-module-casserver18 мая 2026 г.
- CVE-2017-1287223Наблюдать
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow r
СредняяCVSS 5,9Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp1 сент. 2017 г.
- CVE-2017-1286723Наблюдать
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its
СредняяCVSS 5,9Эксплойта нетEPSS 1 %simplesamlphp · simplesamlphp29 авг. 2017 г.