Vulnerabilities > Niif

DATE CVE VULNERABILITY TITLE RISK
2015-08-18 CVE-2015-5513 Cross-site Scripting vulnerability in Niif Shibboleth Authentication
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML via unspecified vectors related to a login link.
network
high complexity
niif CWE-79
2.1
2015-04-21 CVE-2015-3375 Cross-Site Request Forgery (CSRF) vulnerability in Niif Shibboleth Authentication 6.X4.0/7.X4.0
Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete user role matching rules via unspecified vectors.
network
niif CWE-352
5.8
2012-10-31 CVE-2012-4494 Permissions, Privileges, and Access Controls vulnerability in Niif Shibb Auth 7.X4.0
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.
network
niif drupal CWE-264
4.3
2009-12-31 CVE-2009-4527 Permissions, Privileges, and Access Controls vulnerability in Niif Shib Auth
The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser.
local
low complexity
niif drupal CWE-264
4.6