CVE-2018-20857: Zendesk Samlr
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
Affected products
- Zendesk Samlr: before 2.6.2 (fixed in 2.6.2)
Published 2019-07-26. Last modified 2026-06-17.