Logto omits validation of the SAML element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.