Product
high
advisory
Pre-Authentication XXE Vulnerability in SimpleSAMLphp
1 TTP 2 CVEsA proof-of-concept exploit has been published for a pre-authentication XML External Entity (XXE) vulnerability in SimpleSAMLphp and the Saml2 Library, enabling arbitrary file read by unauthenticated remote attackers.
SimpleSAMLphp +1
web-vulnerability
xxe
authentication
1t
2c
high
advisory
SimpleSAMLphp casserver FileSystemTicketStore Path Traversal Vulnerability
2 rules 1 TTPA path traversal vulnerability in SimpleSAMLphp's casserver module allows remote attackers to read and potentially delete arbitrary files outside the ticket directory by manipulating the ticket parameter in CAS validation requests, impacting confidentiality and integrity.
simplesamlphp/simplesamlphp-module-casserver <= 7.0.2
path-traversal
file-deletion
simplesamlphp
2r
1t