CVE-2021-38320
09.09.2021, 19:15
The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simplesamlphp-authentication.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.7.0.
Vendor | Product | Version |
---|---|---|
simplesamlphp_authentication_project | simplesamlphp_authentication | 𝑥 ≤ 0.7.0 |
𝑥
= Vulnerable software versions
References