CVE-2020-1055Medium· 5.5▾ SunlitA cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted reques…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
1.8% → 2.4%
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run scripts in the security context of the current user. This security update addresses the vulnerability by ensuring that ADFS properly sanitizes user inputs.
windows_10 = 1809windows_10 = 1903windows_10 = 1909windows_server_2016 = 1903windows_server_2016 = 1909windows_server_2019Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-83946High· 8.2Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-77490Medium· 6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2020-1166High· 7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service
CVE-2020-1165High· 7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service
CVE-2020-1164High· 7.0An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1158High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory