The Infomaniak Connect for OpenID plugin is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 1.0.2. An attacker with Contributor-level access or higher can inject malicious scripts via the 'endpoint_login' parameter in the infomaniak_connect_generic_auth_url shortcode.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.