Lucene search

K
cvelistMitreCVELIST:CVE-2023-26267
HistoryFeb 21, 2023 - 12:00 a.m.

CVE-2023-26267

2023-02-2100:00:00
mitre
www.cve.org
php-saml-sp
arbitrary files
webserver user
xml
external entities

0.001 Low

EPSS

Percentile

27.8%

php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR.

0.001 Low

EPSS

Percentile

27.8%

Related for CVELIST:CVE-2023-26267