Lucene search

K
wpvulndbHarsh TiwariWPVDB-ID:BE21F355-0E5B-4AD7-9D8F-85E9A0101DDC
HistoryJan 06, 2023 - 12:00 a.m.

miniOrange WordPress SAML SSO Standard < 16.0.8 - Open Redirect in SSO login

2023-01-0600:00:00
Harsh Tiwari
wpscan.com
18
wordpress
saml
sso
open redirect
vulnerability

EPSS

0.001

Percentile

31.5%

The plugin does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in

EPSS

0.001

Percentile

31.5%

Related for WPVDB-ID:BE21F355-0E5B-4AD7-9D8F-85E9A0101DDC