Web Hack List

Collected research

POST to XSS: Leveraging Pseudo Protocols to Gain JavaScript Evaluation in SSO Flows

A protocol-level cross-site scripting pattern in POST-based single sign-on: the OAuth 2.0 form_post response mode and the SAML HTTP-POST binding are implemented as auto-submitting HTML forms, so a redirect_uri or AssertionConsumerService URL registered with a javascript: pseudo-scheme runs script in the identity provider's own origin. Sixteen SSO products were tested and several were vulnerable, among them Keycloak (CVE-2023-6134), enabling authorization code theft and privilege escalation.

Record

Researcher
Lauritz Holtmann
Published by
(Web-)Insecurity Blog
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Lauritz Holtmann, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .