Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5301

16
FAUCET Score

CVE-2020-5301 is an information disclosure vulnerability affecting SimpleSAMLphp versions prior to 1.18.6. It allows an attacker to access the source code of third-party modules. This occurs when a server on a case-insensitive file system (like Windows) processes requests for files ending in ".PHP" (uppercase), bypassing the intended PHP code execution and instead presenting the source code. The vulnerability has a low severity CVSS score of 3.1, indicating a network attack vector with high attack complexity and low impact on confidentiality, with no integrity or availability impact. The attack surface is limited to specific server configurations. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.18.6CPE matchmatch criteria
cpe:2.3:a:simplesamlphp:simplesamlphp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.0LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.3
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.92%
Probability of exploitation in next 30 days
EPSS Percentile
56.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0092 is in the 33rd percentile among its peer group of 1,638 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: simplesamlphp/simplesamlphpFixed in: 1.18.6
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-24m3-w8g9-jwpqlow

Information disclosure of source code in SimpleSAMLphp

Apr 22, 2020

References

github.com / simplesamlphp/simplesamlphp/commit/47968d26a2fd3ed52da70dc09210921d612ce44e
PatchThird Party Advisory
github.com / simplesamlphp/simplesamlphp/security/advisories/GHSA-24m3-w8g9-jwpq
Third Party Advisory