Skip to main content

Vendor archive

niif CVEs

Beta · best-effort

4 CVEs tagged to vendor niif0 Critical, 0 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2015-5513

Published Aug 18, 2015

Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users wit…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-3375

Published Apr 21, 2015

Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for Drupal allows remote attackers to hijack the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4494

Published Oct 31, 2012

The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access rest…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4527

Published Dec 31, 2009

The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1