NA

CVE-2023-26267

Published: 21/02/2023 Updated: 02/03/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

php-saml-sp prior to 1.1.1 and 2.x prior to 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR.

Vulnerable Product Search on Vulmon Subscribe to Product

php-saml-sp project php-saml-sp