A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.8). The affected module is vulnerable to reflected cross-site scripting (XSS) attacks. This could allow an attacker to extract sensitive information by tricking users into accessing a malicious link.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMendix Saml
APPMendix2.3.0 – 2.3.4 (excl.)3.3.0 – 3.3.9 (excl.)
Related vulnerabilities
Mendix SAML – pominięcie uwierzytelnienia przez niewystarczającą weryfikację asercji SAML
Mendix SAML – pominięcie uwierzytelnienia przez niewystarczającą weryfikację asercji SAML
Mendix SAML — niekompletna ochrona przed atakiem replay (CVE-2022-44457)
Mendix SAML — pominięcie uwierzytelnienia przez replay attack
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mend...