Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25057
HistoryApr 22, 2020 - 8:49 a.m.

Information Disclosure

2020-04-2208:49:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

19.4%

simplesamlphp is vulnerable to information disclosure. It does not properly handle a request with an uppercase file extension (‘.PHP’), causing the server to disclose the contents of the file by sending to the browser instead of executing it and therefore leaking the sensitive source code in third-party modules.

CPENameOperatorVersion
simplesamlphp/simplesamlphple1.18.5

0.001 Low

EPSS

Percentile

19.4%