VDB
Sign up

DRUPAL-CONTRIB-2026-146

Details

This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.

The module does not sufficiently sanitize user-supplied data before displaying it in generated HTML leading to a cross-site scripting vulnerability (XSS).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/miniorange_saml
Introduced in: 0Fixed in: 3.2.0

Upgrade drupal/miniorange_saml to 3.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References