Description
Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio-s SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SAML response, without validating it against the registered ACS URL (smc_acs_url) stored in the database for the corresponding service provider client. An attacker who knows the Entity ID of a registered SP client can craft a SAML AuthnRequest with an arbitrary AssertionConsumerServiceURL, causing the IdP to send the signed SAML response -- containing user identity attributes (login name, email, roles, profile fields) -- to an attacker-controlled URL. This issue has been patched in version 5.0.9.
CVSS 8.2EPSS 0.27999999999999997%Risque 0.84
Voir la source- Publication
- 2026-05-07 04:16:30
- Versions concernées
- <5.0.9
- Type
- Core software
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N