PT-2026-81296 · Miniorange · Miniorange Saml Sso+2
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
miniOrange SAML SSO versions prior to 11.0.2
SAML SP Single Sign On – Login with ADFS versions prior to 6.4
SAML SP Single Sign On – SAML SSO login with Google Apps versions prior to 6.4
Description
An authentication bypass exists due to the
mo saml validate signature() function performing a loose boolean check on the integer returned by PHP's openssl verify(). Because an error return value of -1 is evaluated as truthy, it is treated as a successful signature verification. Unauthenticated attackers can log in as any existing user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a malformed signature value that triggers an OpenSSL processing error, leading to the execution of wp set auth cookie() for the targeted account.Recommendations
Update miniOrange SAML SSO to version 11.0.2.
Update SAML SP Single Sign On – Login with ADFS to version 6.4.
Update SAML SP Single Sign On – SAML SSO login with Google Apps to version 6.4.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saml Sp Single Sign On – Login With Adfs
Saml Sp Single Sign On – Saml Sso Login With Google Apps
Miniorange Saml Sso