—
DRUPAL-CONTRIB-2026-146
Details
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module does not sufficiently sanitize user-supplied data before displaying it in generated HTML leading to a cross-site scripting vulnerability (XSS).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/miniorange_saml
Introduced in:
0Fixed in: 3.2.0Upgrade drupal/miniorange_saml to 3.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).