Lucene search

K
cve[email protected]CVE-2022-4496
HistoryJan 30, 2023 - 9:15 p.m.

CVE-2022-4496

2023-01-3021:15:10
web.nvd.nist.gov
23
cve-2022-4496
saml sso
wordpress plugin
open redirect
vulnerability
nvd

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

27.1%

The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.

Affected configurations

Vulners
NVD
Node
miniorangesamlRange16.0.016.0.8
OR
miniorangesamlRange12.0.012.1.0
OR
miniorangesamlRange20.0.020.0.7
VendorProductVersionCPE
miniorangesaml*cpe:2.3:a:miniorange:saml:*:*:*:*:*:*:*:*
miniorangesaml*cpe:2.3:a:miniorange:saml:*:*:*:*:*:*:*:*
miniorangesaml*cpe:2.3:a:miniorange:saml:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "miniOrange",
    "product": "miniOrange WordPress SAML SSO Standard",
    "versions": [
      {
        "status": "affected",
        "version": "16.0.0",
        "lessThan": "16.0.8",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "miniOrange",
    "product": "miniOrange WordPress SAML SSO Premium",
    "versions": [
      {
        "status": "affected",
        "version": "12.0.0",
        "lessThan": "12.1.0",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unaffected"
  },
  {
    "vendor": "miniOrange",
    "product": "miniOrange WordPress SAML SSO Premium MulsiteSite",
    "versions": [
      {
        "status": "affected",
        "version": "20.0.0",
        "lessThan": "20.0.7",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

27.1%

Related for CVE-2022-4496