SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it\'s possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.
Metrics
CVSS Version: 3.1 |
Base Score: 8.3 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L