OAuth Single Sign On – SSO (OAuth Client) Premium < 38.4.9 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack ### PoC The PoC will be display ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) Premium < 38.4.9 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attackRead More ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) Standard < 28.4.9 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack ### PoC The PoC will be display ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) Standard < 28.4.9 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attackRead More ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) Free < 6.24.2 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack ### PoC The PoC will be display ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) Enterprise < 48.4.9 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack ### PoC The PoC will be display ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) Enterprise < 48.4.9 – IdP Deletion via CSRF

The plugin does not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attackRead More ...

Continue Reading
OAuth Single Sign On – SSO (OAuth Client) < 6.24.2 – IdP Discard via CSRF

The plugin does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack ### PoC The PoC will be displayed o ...

Continue Reading

Back to Main

Subscribe for the latest news: