Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18121

Опубликовано: 02 фев. 2018
Источник: debian

Описание

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simplesamlphpfixed1.15.0-1package

Примечания

  • https://simplesamlphp.org/security/201709-01

  • https://github.com/simplesamlphp/simplesamlphp/commit/34e1bdb7660c0c9b627f8e5f0ca224a6afe641a8 (v1.14.16)

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.

CVSS3: 6.1
nvd
около 8 лет назад

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.

CVSS3: 6.1
github
больше 3 лет назад

SimpleSAMLphp XSS Vulnerability