VDB
Sign up
—

DRUPAL-CONTRIB-2026-007

Details

This module enables you to turn a Drupal install into the Central Authentication System (CAS). It makes your database the primary location for other systems to use for authentication in a SSO environment.

The module doesn't sufficiently sanitize user-supplied field values configured to be included as attributes in a CAS server response.

This vulnerability is mitigated by the fact that an attacker must be authenticated, have the ability to enter XML into a user entity field, and that field be configured as a CAS Attribute source leading to an XML Element Injection vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/cas_server
Introduced in: 0Fixed in: 2.0.3

Upgrade drupal/cas_server to 2.0.3 or newer (ecosystem packagist:https://packages.drupal.org/8).

References