A vulnerability was found in Shibboleth Service Provider up to 3.5.0. It has been declared as critical. Affected is the function
SQLString
of the file odbc-store.cpp. Executing manipulation can lead to sql injection.
This vulnerability is handled as CVE-2025-9943. The attack can be executed remotely. There is not any exploit available.