CVE

CVE-2018-20857

CVE-2018-20857

Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!—->. and then the attacker’s domain name.

Source: CVE-2018-20857

Exit mobile version