simplesamlphp kayıtları
simplesamlphp üreticisine ait 35 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %97,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-347 Improper Verification of Cryptographic Signature4
- CWE-20 Improper Input Validation3
- CWE-384 Session Fixation2
- CWE-345 Insufficient Verification of Data Authenticity2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
35 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-6521İstismar yok | The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte charsimplesamlphp · simplesamlphp | Kritik9,8 | — | %3,1 | 1 Şub 2018 |
40Planlayın | CVE-2017-12868İstismar yok | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attasimplesamlphp · simplesamlphp · CWE-384 | Kritik9,8 | — | %2,1 | 1 Eyl 2017 |
39İzleyin | CVE-2017-12873İstismar yok | SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified othsimplesamlphp · simplesamlphp · CWE-384 | Kritik9,8 | — | %1,7 | 1 Eyl 2017 |
37İzleyin | CVE-2016-9814İstismar yok | The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x bsimplesamlphp · simplesamlphp · CWE-399 | Kritik9,1 | — | %2,4 | 16 Şub 2017 |
36İzleyin | CVE-2019-3465İstismar yok | Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographicsimplesamlphp · simplesamlphp · CWE-347 | Yüksek8,8 | — | %3,0 | 7 Kas 2019 |
35İzleyin | CVE-2024-52596İstismar yok | SimpleSAMLphp xml-common XXE vulnerabilitysimplesamlphp · xml-common · CWE-611 | Yüksek8,8 | — | %1,0 | 2 Ara 2024 |
33İzleyin | CVE-2024-52806Kavram kanıtı | SimpleSAMLphp SAML2 has an XXE in parsing SAML messagessimplesamlphp · saml2 · CWE-611 | Yüksek8,3 | — | %0,4 | 2 Ara 2024 |
32İzleyin | CVE-2018-7711İstismar yok | HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utisimplesamlphp · simplesamlphp · CWE-347 | Yüksek8,1 | — | %1,2 | 5 Mar 2018 |
32İzleyin | CVE-2017-18122İstismar yok | A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16.simplesamlphp · simplesamlphp · CWE-347 | Yüksek8,1 | — | %1,1 | 2 Şub 2018 |
32İzleyin | CVE-2026-32600İstismar yok | xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryptionsimplesamlphp · xml-security · CWE-354 | Yüksek8,2 | — | %0,2 | 16 Mar 2026 |
31İzleyin | CVE-2017-12869İstismar yok | The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an asimplesamlphp · simplesamlphp · CWE-20 | Yüksek7,5 | — | %2,4 | 1 Eyl 2017 |
31İzleyin | CVE-2018-6519İstismar yok | The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerabsimplesamlphp · saml2 · CWE-74 | Yüksek7,5 | — | %1,7 | 1 Şub 2018 |
30İzleyin | CVE-2017-12874İstismar yok | The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signatsimplesamlphp · infocard module · CWE-20 | Yüksek7,5 | — | %1,3 | 1 Eyl 2017 |
30İzleyin | CVE-2018-7644İstismar yok | The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowsimplesamlphp · simplesamlphp · CWE-347 | Yüksek7,5 | — | %1,2 | 5 Mar 2018 |
30İzleyin | CVE-2011-4625İstismar yok | simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decryptsimplesamlphp · simplesamlphp · CWE-755 | Yüksek7,5 | — | %0,7 | 6 Kas 2019 |
30İzleyin | CVE-2023-49087İstismar yok | Validation of SignedInfosimplesamlphp · saml2 · CWE-345 | Yüksek7,5 | — | %0,2 | 30 Kas 2023 |
28İzleyin | CVE-2026-49284İstismar yok | SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmatiosimplesamlphp · simplesamlphp · CWE-345 | Yüksek7,1 | — | %0,2 | 17 Tem 2026 |
25İzleyin | CVE-2016-9955İstismar yok | The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 resimplesamlphp · simplesamlphp · CWE-20 | Orta6,3 | — | %1,2 | 16 Şub 2017 |
24İzleyin | CVE-2017-18121İstismar yok | The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft linkssimplesamlphp · simplesamlphp · CWE-79 | Orta6,1 | — | %1,2 | 2 Şub 2018 |
24İzleyin | CVE-2018-6520İstismar yok | SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.simplesamlphp · simplesamlphp · CWE-601 | Orta6,1 | — | %0,9 | 1 Şub 2018 |
24İzleyin | CVE-2010-10002İstismar yok | SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scriptingsimplesamlphp · simplesamlphp-module-openid · CWE-79 | Orta6,1 | — | %0,6 | 1 Oca 2023 |
24İzleyin | CVE-2010-10004İstismar yok | Information Cards Module cross site scriptingsimplesamlphp · information cards module · CWE-79 | Orta6,1 | — | %0,5 | 9 Oca 2023 |
24İzleyin | CVE-2025-65954İstismar yok | SimpleSAMLphp-casserver has an Open Redirect vulnerability via logoutsimplesamlphp · simplesamlphp-module-casserver · CWE-601 | Orta6,1 | — | %0,3 | 18 May 2026 |
23İzleyin | CVE-2017-12872İstismar yok | The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow rsimplesamlphp · simplesamlphp · CWE-200 | Orta5,9 | — | %1,5 | 1 Eyl 2017 |
23İzleyin | CVE-2017-12867İstismar yok | The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend itssimplesamlphp · simplesamlphp · CWE-613 | Orta5,9 | — | %1,3 | 29 Ağu 2017 |
- CVE-2018-652140Planlayın
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte char
KritikCVSS 9,8İstismar yokEPSS %3simplesamlphp · simplesamlphp1 Şub 2018
- CVE-2017-1286840Planlayın
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta
KritikCVSS 9,8İstismar yokEPSS %2simplesamlphp · simplesamlphp1 Eyl 2017
- CVE-2017-1287339İzleyin
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth
KritikCVSS 9,8İstismar yokEPSS %2simplesamlphp · simplesamlphp1 Eyl 2017
- CVE-2016-981437İzleyin
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x b
KritikCVSS 9,1İstismar yokEPSS %2simplesamlphp · simplesamlphp16 Şub 2017
- CVE-2019-346536İzleyin
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic
YüksekCVSS 8,8İstismar yokEPSS %3simplesamlphp · simplesamlphp7 Kas 2019
- CVE-2024-5259635İzleyin
SimpleSAMLphp xml-common XXE vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1simplesamlphp · xml-common2 Ara 2024
- CVE-2024-5280633İzleyin
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
YüksekCVSS 8,3Kavram kanıtıEPSS %0simplesamlphp · saml22 Ara 2024
- CVE-2018-771132İzleyin
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation uti
YüksekCVSS 8,1İstismar yokEPSS %1simplesamlphp · simplesamlphp5 Mar 2018
- CVE-2017-1812232İzleyin
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16.
YüksekCVSS 8,1İstismar yokEPSS %1simplesamlphp · simplesamlphp2 Şub 2018
- CVE-2026-3260032İzleyin
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
YüksekCVSS 8,2İstismar yokEPSS %0simplesamlphp · xml-security16 Mar 2026
- CVE-2017-1286931İzleyin
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an a
YüksekCVSS 7,5İstismar yokEPSS %2simplesamlphp · simplesamlphp1 Eyl 2017
- CVE-2018-651931İzleyin
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerab
YüksekCVSS 7,5İstismar yokEPSS %2simplesamlphp · saml21 Şub 2018
- CVE-2017-1287430İzleyin
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signat
YüksekCVSS 7,5İstismar yokEPSS %1simplesamlphp · infocard module1 Eyl 2017
- CVE-2018-764430İzleyin
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allow
YüksekCVSS 7,5İstismar yokEPSS %1simplesamlphp · simplesamlphp5 Mar 2018
- CVE-2011-462530İzleyin
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt
YüksekCVSS 7,5İstismar yokEPSS %1simplesamlphp · simplesamlphp6 Kas 2019
- CVE-2023-4908730İzleyin
Validation of SignedInfo
YüksekCVSS 7,5İstismar yokEPSS %0simplesamlphp · saml230 Kas 2023
- CVE-2026-4928428İzleyin
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmatio
YüksekCVSS 7,1İstismar yokEPSS %0simplesamlphp · simplesamlphp17 Tem 2026
- CVE-2016-995525İzleyin
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 re
OrtaCVSS 6,3İstismar yokEPSS %1simplesamlphp · simplesamlphp16 Şub 2017
- CVE-2017-1812124İzleyin
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links
OrtaCVSS 6,1İstismar yokEPSS %1simplesamlphp · simplesamlphp2 Şub 2018
- CVE-2018-652024İzleyin
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
OrtaCVSS 6,1İstismar yokEPSS %1simplesamlphp · simplesamlphp1 Şub 2018
- CVE-2010-1000224İzleyin
SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1simplesamlphp · simplesamlphp-module-openid1 Oca 2023
- CVE-2010-1000424İzleyin
Information Cards Module cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1simplesamlphp · information cards module9 Oca 2023
- CVE-2025-6595424İzleyin
SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout
OrtaCVSS 6,1İstismar yokEPSS %0simplesamlphp · simplesamlphp-module-casserver18 May 2026
- CVE-2017-1287223İzleyin
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow r
OrtaCVSS 5,9İstismar yokEPSS %1simplesamlphp · simplesamlphp1 Eyl 2017
- CVE-2017-1286723İzleyin
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its
OrtaCVSS 5,9İstismar yokEPSS %1simplesamlphp · simplesamlphp29 Ağu 2017