When SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor because a user login stored in the session was not verified.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view