CVE-2024-52596

HIGH

Simplesamlphp Xml-common < 1.20.0 - XXE

Title source: rule
STIX 2.1

Description

SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.

Scores

CVSS v4 8.8
EPSS 0.0022
EPSS Percentile 44.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
simplesamlphp/xml-common 0 - 1.20.0Packagist
simplesamlphp/xml-common < 1.20.0
Published Dec 02, 2024
Tracked Since Feb 18, 2026