lib/Auth/Source/External.php in the drupalauth module...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
May 13, 2014
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 28, 2023
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.
References