Cross-site scripting in Admidio - #VU138936
Published: July 21, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the browser of a user who visits a crafted SSO/SAML URL.
The vulnerability exists due to cross-site scripting in the modules/sso/index.php SSO/SAML endpoint when echoing exception messages generated during SAML request processing. A remote attacker can send a specially crafted SSO/SAML request to execute arbitrary JavaScript in the browser of a user who visits a crafted SSO/SAML URL.
Only instances with the SAML SSO feature enabled are vulnerable.