CVE-2012-0040
EPSS 0.55%simplesamlphp - cross site scripting
Published: 1/24/2012Modified: 4/28/2026
Also known as:DEBIAN-CVE-2012-0040
Description
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.
Affected packages (2)
- Debian/simplesamlphpfrom 0, < 1.8.2-1
- Debian/simplesamlphpfrom 0, < 1.6.3-3