Miggo Logo

CVE-2016-3124: SimpleSAMLphp Information leakage issue in the sanitycheck module

5.3

CVSS Score
3.0

Basic Information

EPSS Score
0.4281%
Published
5/14/2022
Updated
4/25/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
simplesamlphp/simplesamlphpcomposer< 1.14.11.14.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability explicitly exists in the sanitycheck module, which is designed to display system information. Since the PHP version leak is the core issue, the controller handling the module's diagnostic output would need to retrieve and display this information. While exact code isn't available, SimpleSAMLphp's MVC structure suggests the main controller method for the module would handle this output. The exposure matches CWE-200's pattern of unauthorized information disclosure via diagnostic interfaces.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T** s*nity****k mo*ul* in Simpl*S*MLp*p ***or* *.**.* *llows r*mot* *tt**k*rs to l**rn t** P*P v*rsion on t** syst*m vi* unsp**i*i** v**tors.

Reasoning

T** vuln*r**ility *xpli*itly *xists in t** `s*nity****k` mo*ul*, w*i** is **si*n** to *ispl*y syst*m in*orm*tion. Sin** t** `P*P` v*rsion l**k is t** *or* issu*, t** *ontroll*r **n*lin* t** mo*ul*'s *i**nosti* output woul* n*** to r*tri*v* *n* *ispl*