CVE-2018-16794
18.09.2018, 21:29
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
Vendor | Product | Version |
---|---|---|
microsoft | active_directory_federation_services | 𝑥 ≤ 4.0 |
𝑥
= Vulnerable software versions
References