CVE-2020-6850: XSS
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6850?
CVE-2020-6850 is a vulnerability in the miniorange-saml-20-single-sign-on plugin for WordPress that allows XSS attacks.
How does CVE-2020-6850 work?
CVE-2020-6850 works by allowing an attacker to inject malicious code into the SAML XML Response to wp-login.php, which can then be executed by unsuspecting users.
What is the severity of CVE-2020-6850?
The severity of CVE-2020-6850 is medium with a CVSS score of 6.1.
What software is affected by CVE-2020-6850?
The miniorange-saml-20-single-sign-on plugin for WordPress versions up to 4.8.84 is affected by CVE-2020-6850.
How can I fix CVE-2020-6850?
To fix CVE-2020-6850, users should update their miniorange-saml-20-single-sign-on plugin to version 4.8.84 or higher.