Impact
The vulnerability resides in lemonldap-ng versions up to 2.23.0, specifically in the CDC.pm library used by the SAML Common Domain Cookie Endpoint. An attacker can manipulate the "url" argument, causing the application to redirect the user to an arbitrary external site. This open redirect flaw is classified as CWE‑601 and can be triggered remotely by sending a crafted request to the affected endpoint.
Affected Systems
The affected product is lemonldap‑ng, a single sign‑on solution for web applications. Versions affected include all releases up to and including 2.23.0. No specific minor or patch versions are listed beyond this range.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available, meaning current estimated exploit probability is unknown. However, the flaw is publicly available, the vendor has not published a fix, and the vulnerability is not listed in CISA KEV. Attackers could exploit it from outside the network, so the risk of discovery and use is realistic. The primary exploit vector is a remote HTTP request that includes a manipulated 'url' parameter leading to a user being redirected to a malicious domain.
OpenCVE Enrichment