socalnick/scn-social-auth
Uses the HybridAuth PHP library to Enable authentication via Google, Facebook, Twitter, Yahoo!, etc for the ZfcUser ZF2 module.
Activity
- Latest release
- 7y ago
- Total releases
- 64
- Cadence
- ~4 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Aug 08, 2012
| Version | Released | |
|---|---|---|
1.22.1
patch
|
1.22.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.22.0
minor
| ||
1.21.1
minor
|
1.21.1
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.20.0
minor
| ||
1.19.1
patch
|
1.19.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.19.0
minor
| ||
1.18.1
patch
|
1.18.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.18.0
minor
|
1.18.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.17.2
patch
| ||
1.17.1
patch
| ||
1.17.0
minor
| ||
1.16.0
minor
| ||
1.15.2
patch
| ||
1.15.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.15.0-rc.1
pre
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.14.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.14.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.12.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.11.3
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.11.2
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.11.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.10.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.7
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.8.4
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.9.4
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.8.3
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.6
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.9.3
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.5
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.8.2
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.9.2
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.4
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.8.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.9.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.9.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.6.4
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.3
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.6.3
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.2
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.6.2
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
GHSA-g6f5-4w43-2x63
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ScnSocialAuth version 1.15.2 has been released and includes a security for this vulnerability. Fix has been applied in https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 Affected versionsAll versions below 1.15.2 are affected. dev-master is fixed starting from https://github.com/SocalNick/ScnSocialAuth/commit/4a00966c41bc37251586d007564c5c891eba3700 ExploitsBecause of missing escaping of the URL param redirect a XSS attack is possible.
For example: Setting the redirect param to ResolutionIf you are using any version of ScnSocialAuth below 1.15.2 please upgrade immediately by running composer update. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.11.0
1.11.1
1.11.2
+ 40 more Show less
1.11.3
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.15.0-rc.1
1.15.0-rc.2
1.15.1
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
Fixed in
1.15.2
References
Updated Dec 04, 2024 · Source: OSV.dev |