Medium severity5.4NVD Advisory· Published Jul 11, 2018· Updated Jun 17, 2026
CVE-2018-8326
CVE-2018-8326
Description
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Open Source Customization for Active Directory Federation Services XSS Vulnerability." This affects Web Customizations.
Affected products
2- Microsoft/Web Customizationsv5Range: Active Directory Federation Services
Patches
Vulnerability mechanics
References
3- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8326nvdPatchVendor Advisory
- www.securityfocus.com/bid/104656nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041266nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.