What the vulnerability does
01Description
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
Explanation of Vulnerability in Simple Terms
The miniOrange SAML SP Single Sign On plugin through version 5.4.3 assigns privileges incorrectly, allowing an unauthenticated attacker to gain high-level access to the site. The vulnerability requires specific network conditions to exploit but does not require user interaction. An attacker can read sensitive data, modify site content, or disrupt service availability.
What an attacker can do
Gain unauthorized administrative access without authentication and read, modify, or delete site data.
Potential impact on your site
An attacker could take full control of your site, steal user data, modify content, or take the site offline.
Conditions required to exploit
Network access to the site; no authentication or user interaction required, but attack complexity is high.
Key dates
External resources
Related vulnerabilities