Forwarding Server Security

Forwarding Server Security

Desktop Central Forwarding server appears to be vulnerable to XSS and Forceful browsing attacks. Is there a way to mitigate this. The default configuration also exposes the DesktopCentral login to the internet, and 2-Factor can be bypassed with the mobile app - all serious security concerns for an internet facing device. How can this be disabled or mitigated?

Thanks!

                New to ADSelfService Plus?