CVE-2019-11066
10.05.2019, 20:29
openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.
Vendor | Product | Version |
---|---|---|
lightopenid_project | lightopenid | 𝑥 ≤ 1.3.1 |
𝑥
= Vulnerable software versions