Security Advisory

CVE-2018-8899

6.1
MEDIUM

Vulnerability Description

IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
Published Date March 22, 2018
Official Source NIST NVD Advisory