CVE-2018-16794

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
18/09/2018
Last modified:
20/11/2018

Description

Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:active_directory_federation_services:*:*:*:*:*:*:*:* 4.0 (including)
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*