A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.
2019-09-11T22:15:17.507
2024-11-21T04:36:22.970
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows_10 | 1803 | Yes |
Operating System | microsoft | windows_10 | 1809 | Yes |
Operating System | microsoft | windows_10 | 1903 | Yes |
Operating System | microsoft | windows_server_2016 | 1803 | Yes |
Operating System | microsoft | windows_server_2016 | 1903 | Yes |
Operating System | microsoft | windows_server_2019 | - | Yes |