Vulnerabilities > CVE-2021-36786 - Insecure Storage of Sensitive Information vulnerability in Miniorange Saml

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
miniorange
CWE-922

Summary

The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.

Vulnerable Configurations

Part Description Count
Application
Miniorange
1

Common Weakness Enumeration (CWE)