Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgcm-m74w-vrfx

Опубликовано: 04 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.

XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.

EPSS

Процентиль: 10%
0.00035
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-91

Связанные уязвимости

CVSS3: 4.2
nvd
3 дня назад

XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.

EPSS

Процентиль: 10%
0.00035
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-91