CVE-2018-8899
EUVD-2018-2050722.03.2018, 05:29
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| identityserver | identityserver4 | 1.0.0 ≤ 𝑥 ≤ 1.5.2 |
| identityserver | identityserver4 | 2.0.0 ≤ 𝑥 ≤ 2.1.2 |
𝑥
= Vulnerable software versions
References