CVE-2018-20857: Zendesk Samlr

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.

Affected products

  • Zendesk Samlr: before 2.6.2 (fixed in 2.6.2)

Published 2019-07-26. Last modified 2026-06-17.