PT-2026-51252 · Unknown · Lemonldap::Ng

·

CVE-2026-12804

·

Published

2026-06-21

·

Updated

2026-06-22

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions lemonldap-ng versions prior to 2.23.1
Description An issue exists in the SAML Common Domain Cookie Endpoint within the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm. A remote attacker can perform a manipulation of the url argument, leading to an open redirect. An open redirect occurs when an application takes a user-provided input and uses it in a redirect without sufficient validation, allowing attackers to redirect users to malicious external sites.
Recommendations Update to a version later than 2.23.0. Avoid using the url argument in the affected SAML Common Domain Cookie Endpoint until the update is applied.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12804

Affected Products

Lemonldap::Ng