Vulnerabilities (CVE)

Filtered by vendor Miniorange Subscribe
Filtered by product Saml Sp Single Sign On
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6850 1 Miniorange 1 Saml Sp Single Sign On 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
CVE-2019-12346 1 Miniorange 1 Saml Sp Single Sign On 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.