Project
Date
Severity
Critical
Vulnerability
Cross-site scripting
Affected versions
<7.x-2.73
Description
The SAML SSO - Service Provider module enables you to perform SAML protocol-based single sign-on (SSO) on a Drupal site.
The module doesn't sufficiently sanitize user input, leading to a reflected Cross-site scripting (XSS) vulnerability.
Solution
Install the latest version.
If you use the SAML SSO - Service Provider module for Drupal 7, upgrade to SAML SSO - Service Provider 7.x-2.73:
Reported by
Drew Webber (mcdruid) of the Drupal Security Team
Fixed by
- Sudhanshu Dhage (sudhanshu0542)
- Tag1 D7ES Security Team
Coordinated by
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Tag1 D7ES Security Team