RSS   Vulnerabilities for 'Phpcas'   RSS

2019-12-05
 
CVE-2012-1105

CWE-200
 

 
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.

 
2017-07-17
 
CVE-2017-1000071

CWE-287
 

 
Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

 

 >>> Vendor: Apereo 4 Products
Central authentication service
Phpcas
Opencast
Bw-calendar-engine


Copyright 2024, cxsecurity.com

 

Back to Top