Description
|
|
A cross-site scripting vulnerability has been identified in the Active Directory Federation Services (ADFS) service of Windows Server.
A remote attacker can enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript/HTML code with victim's rights.
This vulnerability, exploitable via the "wct" parameter of the "/adfs/ls" page, stems from an improper handling of the HTML encoding of HTTP responses.
A proof of concept is available.
|