Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silently enabled via \LIBXML_DTDLOAD | \LIBXML_DTDATTR.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
php-saml-sp 代码问题漏洞
Vulnerability Description
php-saml-sp是一个 SAML 服务提供商(SP)。可以从现有的 PHP 应用程序中使用 SAML 身份验证。 php-saml-sp 2.1.1 (2.x)之前版本、1.1.1 (1.x)之前版本存在安全漏洞,该漏洞源于允许以网络服务器用户身份读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A