PT-2026-51252 · Unknown · Lemonldap::Ng
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
lemonldap-ng versions prior to 2.23.1
Description
An issue exists in the SAML Common Domain Cookie Endpoint within the library
lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm. A remote attacker can perform a manipulation of the url argument, leading to an open redirect. An open redirect occurs when an application takes a user-provided input and uses it in a redirect without sufficient validation, allowing attackers to redirect users to malicious external sites.Recommendations
Update to a version later than 2.23.0.
Avoid using the
url argument in the affected SAML Common Domain Cookie Endpoint until the update is applied.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lemonldap::Ng