云虫漏洞库

CVE-2026-80200 - Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks. - 漏洞详情

漏洞编号:CVE-2026-80200

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-80200

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-601

发布/更新时间:2026-08-26 / 2026-08-28

漏洞描述

Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.

相关链接

相关漏洞

« 返回首页