Impact
Admidio versions prior to 5.0.11 contain a reflected cross‑site scripting flaw in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. The vulnerability exploits the fact that exception data is displayed without proper encoding, allowing an attacker to inject arbitrary JavaScript code. This flaw is identified as CWE‑79. An attacker who can send crafted requests to the SSO/SAML endpoint can execute attacker‑controlled script in the victim’s browser, potentially hijacking user sessions and carrying out further attacks such as credential theft or stealth data exfiltration.
Affected Systems
The affected product is Admidio provided by the vendor Admidio. All releases earlier than 5.0.11 are vulnerable. Versions 5.0.11 and later contain the fix that prevents the reflected XSS by sanitizing exception output. Users running these earlier versions should be notified of the vulnerability
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. No EPSS score is available, so the current likelihood of exploitation cannot be quantified. The flaw can be triggered via normal web traffic to the SSO/SAML endpoint; it does not require authentication. Because the attacker can inject JavaScript into the response, the attack is likely remote and can compromise confidentiality and integrity of user sessions. The vulnerability is not listed in the CISA KEV catalog, and no publicly available proof‑of‑concept is reported in the references.
OpenCVE Enrichment