CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.
CVE
CVE-2016-2049
Severity
HIGH
CVSS
8.8
EPSS
2.17%
Original NVD Description
examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.