CVE-2013-4552
drupalauth <1.2.2 - Auth Bypass
Title source: llmDescription
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.
Scores
EPSS
0.0048
EPSS Percentile
64.7%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
drupalauth_project/drupalauth
< 1.2.1
Timeline
Published
May 13, 2014
Tracked Since
Feb 18, 2026