← Back

Drupalauth

drupalauth

Vendor: Drupalauth Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Drupalauth Project
1Drupalauth
May 6, 2026
May 13, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.