Lucene search

K
wpvulndbHarsh TiwariWPVDB-ID:E6C4C8C7-1DCD-45BF-8582-F12ACCCA6FAC
HistoryJan 06, 2023 - 12:00 a.m.

miniOrange WordPress SAML SSO Premium Multisite < 20.0.7 - Open Redirect in SSO login

2023-01-0600:00:00
Harsh Tiwari
wpscan.com
7
wordpress
saml
sso
open redirect
vulnerability

EPSS

0.001

Percentile

31.5%

The plugin does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.

EPSS

0.001

Percentile

31.5%

Related for WPVDB-ID:E6C4C8C7-1DCD-45BF-8582-F12ACCCA6FAC