312
VMScore

CVE-2018-8547

Published: 14/11/2018 Updated: 14/12/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 8.1 -

microsoft windows rt 8.1 -

microsoft windows server 2012 r2

microsoft windows server 2016 -

microsoft windows 10 1709

microsoft windows 10 1809

microsoft windows server 2019 -

microsoft windows server 2016 1709

microsoft windows 10 1607

microsoft windows 10 1803

microsoft windows server 2016 1803