XML Comment Attack in Zendesk Samlr Plugin Allows User Enumeration

XML Comment Attack in Zendesk Samlr Plugin Allows User Enumeration

CVE-2018-20857 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.

Learn more about our User Device Pen Test.