VYPR

Drupal 7 Miniorange SAML Sp

by Xecuify

CVEs (1)

  • CVE-2022-26493CriJun 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML…