CVE-2024-52596

HIGH

simplesamlphp/xml-common < 1.20.0 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.

Scores

CVSS v4 8.8
EPSS 0.0097
EPSS Percentile 57.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (2)
simplesamlphp/xml-common 0 - 1.20.0Packagist
simplesamlphp/xml-common < 1.20.0
Published Dec 02, 2024
Tracked Since Feb 18, 2026