AI Score
Confidence
Low
EPSS
Percentile
57.0%
The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
drupal.org/node/216022
secunia.com/advisories/28717
www.securityfocus.com/bid/27542
www.vupen.com/english/advisories/2008/0373/references