High severity8.6NVD Advisory· Published Sep 18, 2018· Updated Jun 17, 2026
CVE-2018-16794
CVE-2018-16794
Description
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/149376/Microsoft-ADFS-4.0-Windows-Server-2016-Server-Side-Request-Forgery.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2018/Sep/13nvdExploitMailing ListThird Party Advisory
- seclists.org/bugtraq/2018/Sep/26nvdExploitMailing ListThird Party Advisory
- www.securityfocus.com/bid/105378nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.