Executive brief
The miniorange_saml module for Drupal allows organizations to configure single sign-on using SAML 2.0 authentication. A flaw in URL validation allows attackers to redirect authenticated users to external websites, enabling phishing attacks or distributing malicious content with false credibility.
Technical details
The miniorange_saml module fails to sufficiently validate user-supplied URLs before performing post-authentication redirects, enabling an open redirect attack. An unauthenticated attacker can craft URLs to redirect users to external malicious sites after they complete SAML authentication. This vulnerability affects all versions before 3.2.0 and is fixed in version 3.2.0 and later.
Affected products
- miniOrange SAML SSO - Service Provider before 3.2.0
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fixed in version 3.2.0