{"id":"CVE-2025-65954","title":"SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module","summary":"SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as tr…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-601"],"vendor":"simplesamlphp","product":"simplesamlphp-module-casserver","affected":["simplesamlphp-module-casserver < 6.3.1","simplesamlphp-module-casserver = 7.0.0"],"patched":["simplesamlphp-module-casserver 6.3.1"],"published":"2026-05-18","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:10:00.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-65954","references":[{"url":"https://github.com/simplesamlphp/simplesamlphp-module-casserver/commit/0462f50f00b3bb300d83067d11b74146a57bb8e0","label":"security-advisories@github.com"},{"url":"https://github.com/simplesamlphp/simplesamlphp-module-casserver/commit/fb6c6f1c7b9e757c93c5c306e1d36405e64f6dc5","label":"security-advisories@github.com"},{"url":"https://github.com/simplesamlphp/simplesamlphp-module-casserver/security/advisories/GHSA-cvrm-5hp6-h523","label":"security-advisories@github.com"},{"url":"https://github.com/simplesamlphp/simplesamlphp-module-casserver/security/advisories/GHSA-cvrm-5hp6-h523","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00269,"epssPercentile":0.17232,"ingestedAt":"2026-09-30T21:25:07.731Z","slug":"CVE-2025-65954","body":"## Overview\n\nSimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or shows a \"you've been logged out\" page with a link to continue to that url. Impacted configs include 'enable_logout' => true, and 'skip_logout_page' -> true. This issue has been resolved in versions 6.3.1 and 7.0.0.\n\n## Affected\n\n- `simplesamlphp-module-casserver < 6.3.1`\n- `simplesamlphp-module-casserver = 7.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `simplesamlphp-module-casserver 6.3.1`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}