📦

openid

Vendor: peter_wolanin

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 1 Remote Access
Total CVEs 13 Total Indexed
Avg. EPSS 1.55% Exploit Prob.
Latest CVE CVE-2023-50770 Dec 13

Security Vulnerability Index

Page 2 / 2
6.8 CVSS

Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authentication of unspecified victims to delete OpenID identities via unknown vectors.

EPSS: 0.63%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 1.06%
5.0 CVSS

The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.

EPSS: 1.05%
6.8 CVSS
CVE-2007-5173
RCE Exploit Found

PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter.

EPSS: 2.80%
7.5 CVSS

OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.

EPSS: 1.27%
6.8 CVSS

Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enabled site via unspecified vectors related to an arbitrary remote web site and cached tokens, after the user has signed into an OpenID server, logged into the OpenID enabled site, and then logged out of the OpenID enabled site.

EPSS: 1.42%