Description
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.
Problem types
CWE-91 XML Injection (aka Blind XPath Injection)
Product status
0.0.0 (semver) before 2.0.3
2.1.0 (semver) before 2.1.2
Credits
Gaël Gosset (gaëlg)
Ted Cooper (elc)
Gaël Gosset (gaëlg)
Jaap Jansma (jaapjansma)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2026-007