CVE-2018-6521
9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.05% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-02-02 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| simplesamlphp | simplesamlphp |
References
- https://lists.debian.org/debian-lts-announce/2018/02/msg00008.html
- https://simplesamlphp.org/security/201801-03
- https://www.debian.org/security/2018/dsa-4127
- https://lists.debian.org/debian-lts-announce/2018/02/msg00008.html
- https://simplesamlphp.org/security/201801-03
- https://www.debian.org/security/2018/dsa-4127
→ the Explorer · watch your stack · NVD