CVE-2010-10004

A

vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.0 is able to address this issue. The identifier of the patch is f6bfea49ae16dc6e179df8306d39c3694f1ef186. It is recommended to upgrade the affected component. The identifier VDB-217661 was assigned to this vulnerability.

Configurations

Configuration 1 (hide)

cpe:2.3:a:simplesamlphp:information_cards_module:*:*:*:*:*:simplesamlphp:*:*

History

21 Nov 2024, 01:13

Type Values Removed Values Added
References () https://github.com/simplesamlphp/simplesamlphp-module-infocard/commit/f6bfea49ae16dc6e179df8306d39c3694f1ef186 - Patch, Third Party Advisory () https://github.com/simplesamlphp/simplesamlphp-module-infocard/commit/f6bfea49ae16dc6e179df8306d39c3694f1ef186 - Patch, Third Party Advisory
References () https://github.com/simplesamlphp/simplesamlphp-module-infocard/releases/tag/v1.0 - Release Notes, Third Party Advisory () https://github.com/simplesamlphp/simplesamlphp-module-infocard/releases/tag/v1.0 - Release Notes, Third Party Advisory
References () https://vuldb.com/?ctiid.217661 - Third Party Advisory () https://vuldb.com/?ctiid.217661 - Third Party Advisory
References () https://vuldb.com/?id.217661 - Third Party Advisory () https://vuldb.com/?id.217661 - Third Party Advisory
CVSS v2 : 4.0
v3 : 6.1
v2 : 4.0
v3 : 3.5

Information

Published : 2023-01-09 08:15

Updated : 2024-11-21 01:13


NVD link : CVE-2010-10004

Mitre link : CVE-2010-10004

CVE.ORG link : CVE-2010-10004


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')