Skip to main content

Vendor archive

simplesamlphp CVEs

Beta · best-effort

31 CVEs tagged to vendor simplesamlphp4 Critical, 9 High, 14 Medium, 4 Low, 0 Unrated.

CVE-2017-12867

Published Aug 29, 2017

The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the pr…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3124

Published Feb 7, 2017

The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0908

Published Jan 24, 2012

Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0040

Published Jan 24, 2012

Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-31 of 31 CVEsPage 2 of 2