ZeroHour

CVE-2018-8899

CVSS 3.0
6.1 medium
EPSS
1%p67
Published
()
Modified
Description

IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.

Vendors
identityserver
Products
identityserver4
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.