Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal OpenID Module 'claimed_id' 身份认证绕过漏洞
Vulnerability Description
Drupal OpenID module 5.x-1.0以及之前版本未能恰当的验证openid来源返回的claimed_id,这使得与其他来源相关的远程OpenID供应商能够欺骗整个域上的openid身份认证。
CVSS Information
N/A
Vulnerability Type
N/A