PT-2026-67414 · Lightsaml+1 · Lightsaml+1
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Admidio versions prior to 5.0.11
Description
A reflected cross-site scripting issue exists in the SSO/SAML endpoint. The system echoes unencoded exception messages in the HTTP response, allowing unauthenticated attackers to inject arbitrary JavaScript. This can be achieved through SAML Issuer elements or LightSaml library parameters, potentially leading to code execution in users' browsers and session hijacking.
Recommendations
Update to version 5.0.11 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admidio
Lightsaml