VDB
Sign up
—

DRUPAL-CONTRIB-2026-018

Details

This module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site.

The module doesn't sufficiently sanitize user input, leading to a reflected Cross-site scripting (XSS) vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/miniorange_saml
Introduced in: 0Fixed in: 3.1.3

Upgrade drupal/miniorange_saml to 3.1.3 or newer (ecosystem packagist:https://packages.drupal.org/8).

References