Security Advisory
CVE-2018-8899
6.1
MEDIUM
Vulnerability Description
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
Published Date
March 22, 2018
Official Source
NIST NVD Advisory