The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user.
This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs.
Project Subscriptions
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-11948 | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'. | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs. |
| Title | Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability | |
| First Time appeared |
Microsoft windows 10 1809
Microsoft windows 10 1909 Microsoft windows Server 1903 Microsoft windows Server 1909 |
|
| CPEs | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_1909:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft windows 10 1809
Microsoft windows 10 1909 Microsoft windows Server 1903 Microsoft windows Server 1909 |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-19T16:33:26.703Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1055
Updated: 2024-08-04T06:25:00.712Z
Status : Modified
Published: 2020-05-21T23:15:12.133
Modified: 2026-08-19T17:17:10.260
Link: CVE-2020-1055
No data.
OpenCVE Enrichment
No data.
EUVD