CVE-2020-5301 is an information disclosure vulnerability affecting SimpleSAMLphp versions prior to 1.18.6. It allows an attacker to access the source code of third-party modules. This occurs when a server on a case-insensitive file system (like Windows) processes requests for files ending in ".PHP" (uppercase), bypassing the intended PHP code execution and instead presenting the source code. The vulnerability has a low severity CVSS score of 3.1, indicating a network attack vector with high attack complexity and low impact on confidentiality, with no integrity or availability impact. The attack surface is limited to specific server configurations. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.18.6CPE matchmatch criteria | cpe:2.3:a:simplesamlphp:simplesamlphp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.