{ "id": "CVE-2024-36383", "sourceIdentifier": "cve@mitre.org", "published": "2024-05-27T11:15:08.710", "lastModified": "2024-05-27T11:15:08.710", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage." } ], "metrics": {}, "references": [ { "url": "https://servicedesk.logpoint.com/hc/en-us/articles/19128172110621-Arbitrary-file-deletion-through-URL-Injection-to-SAML-SSO-URL-Response", "source": "cve@mitre.org" } ] }