CVE-2013-4552
13.05.2014, 15:55
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.Enginsight
Vendor | Product | Version |
---|---|---|
drupalauth_project | drupalauth | 𝑥 ≤ 1.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References