Collected research
SAML XML Injection
Explains how unsafe interpolation of user-controlled values into SAML XML lets an attacker alter assertions before the identity provider signs them. It shows probes and exploit patterns for request IDs and user attributes, including injected roles, usernames or whole assertions that can cause account takeover or privilege escalation.
Record
- Researcher
- Adam Roberts
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Roberts, first published at the original source. Preserved copies are kept so the citation survives its host.