Exploit/Advisories Cybersecurity study of the dark web exposes vulnerability to machine identities -- ScienceDaily

Published on July 26th, 2019 📆 | 3310 Views ⚑

0

Zendesk Samlr up to 2.6.1 XML Node name_id unknown vulnerability


iSpeech

CVSS Meta Temp Score Current Exploit Price (โ‰ˆ)
5.3 $0-$5k

A vulnerability was found in Zendesk Samlr up to 2.6.1. It has been rated as problematic. Affected by this issue is an unknown code of the component XML Node Handler. The manipulation of the argument name_id with the input value user@example.com leads to a unknown weakness. The impact remains unknown.

The weakness was disclosed 07/26/2019. This vulnerability is handled as CVE-2018-20857 since 07/26/2019. Technical details are known, but there is no available exploit. The structure of the vulnerability defines a possible price range of USD $0-$5k at the moment (estimation calculated on 07/26/2019).

Upgrading to version 2.6.2 eliminates this vulnerability.

Vendor

Name

Class: Unknown
Local: Yes
Remote: No

Availability: ๐Ÿ”’
Status: Not defined

Price Prediction: ๐Ÿ”
Current Price Estimation: ๐Ÿ”’


0-Day unlock unlock unlock unlock
Today unlock unlock unlock unlock

Threat Intelligenceinfoedit

Threat: ๐Ÿ”
Adversaries: ๐Ÿ”
Geopolitics: ๐Ÿ”
Economy: ๐Ÿ”
Predictions: ๐Ÿ”
Remediation: ๐Ÿ”Recommended: Upgrade
Status: ๐Ÿ”

0-Day Time: ๐Ÿ”’

Upgrade: Samlr 2.6.2

07/26/2019 Advisory disclosed
07/26/2019 +0 days VulDB entry created
07/26/2019 +0 days CVE assigned
07/26/2019 +0 days VulDB last update
CVE: CVE-2018-20857 (๐Ÿ”’)Created: 07/26/2019 06:00 PM
Complete: ๐Ÿ”

Download the whitepaper to learn more about our service!

https://vuldb.com/?id.138842

Tagged with: โ€ข โ€ข โ€ข



Comments are closed.