Intel

AIKIDO-2026-10255

drupal/miniorange_saml is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2026-3217 Published Feb 26, 2026

91

Critical Risk

This Affects:

PHPdrupal/miniorange_saml
0.0.1 - 3.1.2
Fixed in 3.1.3
Are you affected? Scan for Free

TL;DR

This module enables SAML protocol-based single sign-on (SSO) on a Drupal site and does not sufficiently sanitize user input, resulting in a reflected cross-site scripting (XSS) vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/miniorange_saml is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 3.1.2.

How to fix this

Upgrade the drupal/miniorange_saml library to the patch version.