Vulnerabilities > Microsoft > Active Directory Federation Services > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-18 CVE-2018-16794 Server-Side Request Forgery (SSRF) vulnerability in Microsoft Active Directory Federation Services
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
network
low complexity
microsoft CWE-918
8.6