CVE-2021-28963

Publication date

2021-03-22 07:02:05

Family

mitre

State

PUBLISHED

Description

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.