CVE-2017-18121: XSS
Published Aug 25, 2017
·Updated
Cross Site Scripting (XSS) in the consentAdmin module
Other sources
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.
Affected Software
7 affected componentsFixes available
composer/simplesamlphp/simplesamlphp>=1.12.0, <1.13.0, >=1.13.0, <1.14.0, >=1.14.0, <1.14.16
debian/simplesamlphp
1.16.3-1+deb10u21.16.3-1+deb10u11.19.0-11.19.7-1
composer/simplesamlphp/simplesamlphp>=1.12.0<1.14.16
1.14.16
SimpleSAMLphp SimpleSAMLphp<=1.14.15
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Aug 25, 2017
Advisory Published
11:35 AM
Feb 2, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Feb 3, 2018
Data Sourced
10:57 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-18121?
CVE-2017-18121 is classified as a high severity vulnerability due to its potential to execute arbitrary JavaScript code in a victim's browser.
2
How do I fix CVE-2017-18121?
To fix CVE-2017-18121, upgrade SimpleSAMLphp to version 1.14.16 or later.
3
Which versions of SimpleSAMLphp are affected by CVE-2017-18121?
CVE-2017-18121 affects versions of SimpleSAMLphp from 1.12.0 up to and including 1.14.15.
4
What type of vulnerability is CVE-2017-18121?
CVE-2017-18121 is a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2017-18121 affect users of Debian Linux?
Yes, CVE-2017-18121 can affect users of Debian Linux using vulnerable versions of SimpleSAMLphp.