—
DRUPAL-CONTRIB-2026-018
Details
This module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site.
The module doesn't sufficiently sanitize user input, leading to a reflected Cross-site scripting (XSS) vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/miniorange_saml
Introduced in:
0Fixed in: 3.1.3Upgrade drupal/miniorange_saml to 3.1.3 or newer (ecosystem packagist:https://packages.drupal.org/8).