CVE-2022-4496
Last modified
CVE-2022-4496 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Miniorange | Saml Sp Single Sign On | >= 12.0.0, < 12.1.0 |
| Miniorange | Saml Sp Single Sign On | >= 16.0.0, < 16.0.8 |
| Miniorange | Saml Sp Single Sign On | >= 20.0.0, < 20.0.7 |
References
- https://wpscan.com/vulnerability/af2e30c7-0787-4fe2-97ee-bc616f7178a1Third Party Advisory
- https://wpscan.com/vulnerability/be21f355-0e5b-4ad7-9d8f-85e9a0101ddcThird Party Advisory
- https://wpscan.com/vulnerability/e6c4c8c7-1dcd-45bf-8582-f12accca6facThird Party Advisory
- https://wpscan.com/vulnerability/af2e30c7-0787-4fe2-97ee-bc616f7178a1Third Party Advisory
- https://wpscan.com/vulnerability/be21f355-0e5b-4ad7-9d8f-85e9a0101ddcThird Party Advisory
- https://wpscan.com/vulnerability/e6c4c8c7-1dcd-45bf-8582-f12accca6facThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4496?
How severe is CVE-2022-4496?
How do I fix CVE-2022-4496?
Are you affected by CVE-2022-4496?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
