phpCAS authentication library < 1.6.0 - Service Hostname Discovery Exploitation
highThe phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the...
- CVSS:
- 8
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Nov 1, 2022