XML Comment Attack in Zendesk Samlr Plugin Allows User Enumeration
CVE-2018-20857 · MEDIUM Severity
AV:N/AC:L/AU:N/C:N/I:P/A:N
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
Learn more about our User Device Pen Test.