Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6385
HistoryMay 25, 2018 - 6:37 a.m.

Cross-site Scripting (XSS)

2018-05-2506:37:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.002 Low

EPSS

Percentile

55.7%

simplesamlphp is vulnerable to cross-site scripting (XSS) attacks. A malicious user can craft URLs that include Javascript to pass to another user for execution through the setConsentText function in the consentAdmin module. This vulnerability requires the consentAdmin module to be enabled and configured in an Identity Provider.

CPENameOperatorVersion
simplesamlphp/simplesamlphple1.14.15