The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user.
This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-11948 | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'. |
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'. | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs. |
| Title | Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability | |
| First Time appeared |
Microsoft windows 10 1809
Microsoft windows 10 1909 Microsoft windows Server 1903 Microsoft windows Server 1909 |
|
| CPEs | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_1909:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft windows 10 1809
Microsoft windows 10 1909 Microsoft windows Server 1903 Microsoft windows Server 1909 |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-19T16:33:26.703Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1055
Updated: 2024-08-04T06:25:00.712Z
Status : Modified
Published: 2020-05-21T23:15:12.133
Modified: 2026-08-19T17:17:10.260
Link: CVE-2020-1055
No data.
OpenCVE Enrichment
No data.
EUVD