Web Hack List

Collected research

SAML XML Injection

Explains how unsafe interpolation of user-controlled values into SAML XML lets an attacker alter assertions before the identity provider signs them. It shows probes and exploit patterns for request IDs and user attributes, including injected roles, usernames or whole assertions that can cause account takeover or privilege escalation.

Record

Researcher
Adam Roberts

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Roberts, first published at the original source. Preserved copies are kept so the citation survives its host.