XML Encryption Flaw in SimpleSAMLphp Affects Multiple Versions
CVE-2011-4625
7.5HIGH
What is CVE-2011-4625?
SimpleSAMLphp before version 1.6.3 (squeeze) and before 1.8.2 (sid) contains a vulnerability that improperly manages XML encryption. This flaw could enable remote attackers to decrypt sensitive messages or forge modifications to the original messages, compromising data integrity in applications relying on this software.
Affected Version(s)
simplesamlphp 1.13.1-2
