CVE-2013-4552: Drupalauth Project Drupalauth
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie.
Affected products
- Drupalauth Project Drupalauth: up to and including 1.2.1
Published 2014-05-13. Last modified 2026-06-16.