CVE-2013-4552: Drupalauth Project Drupalauth

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.

Affected products

Published 2014-05-13. Last modified 2026-06-16.