CyberRota Analysis
AI-GeneratedActive Directory Federation Services (AD FS) is vulnerable to cross-site scripting due to improper input neutralization during web page generation, enabling an authorized attacker to execute spoofing attacks over the network. This vulnerability poses a medium risk, as it could compromise user sessions and lead to unauthorized actions. Organizations utilizing AD FS should prioritize remediation to protect against potential exploitation.
Original NVD Description
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
Related CVEs
Other vulnerabilities affecting the same vendor(s)