A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.
| Software | From | Fixed in |
|---|---|---|
| microsoft / windows_10 | 1803 | 1803.x |
| microsoft / windows_server_2016 | 1803 | 1803.x |
| microsoft / windows_10 | 1809 | 1809.x |
| microsoft / windows_server_2016 | 1903 | 1903.x |
| microsoft / windows_10 | 1903 | 1903.x |