Drupal SAML SSO - Service Provider Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the Drupal SAML SSO - Service Provider module, affecting versions prior to 3.1.3. The issue arises from improper input sanitization, allowing for reflected XSS attacks.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Remediation
Users of the Drupal SAML SSO - Service Provider module should upgrade to version 3.1.3.
Added: Mar 25, 2026, 4:56 PM
Updated: Mar 25, 2026, 4:56 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.7exploitability
6.2remediation
0.0relevance
4.7threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
