First published: Mon Feb 17 2020(Updated: )
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
miniOrange SAML SP Single Sign On | <4.8.84 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6850 is a vulnerability in the miniorange-saml-20-single-sign-on plugin for WordPress that allows XSS attacks.
CVE-2020-6850 works by allowing an attacker to inject malicious code into the SAML XML Response to wp-login.php, which can then be executed by unsuspecting users.
The severity of CVE-2020-6850 is medium with a CVSS score of 6.1.
The miniorange-saml-20-single-sign-on plugin for WordPress versions up to 4.8.84 is affected by CVE-2020-6850.
To fix CVE-2020-6850, users should update their miniorange-saml-20-single-sign-on plugin to version 4.8.84 or higher.