CVE-2019-11066
EUVD-2019-277310.05.2019, 20:29
openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lightopenid_project | lightopenid | 𝑥 ≤ 1.3.1 |
𝑥
= Vulnerable software versions