CVE-2018-8763Cross-site Scripting in Ldap Account Manager

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 36.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 14

Description

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

debiandebian/ldap-account-manager< ldap-account-manager 6.3-1 (bookworm)

Also affects: Debian Linux 7.0, 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-pcvp-8j6c-wg38: Roland Gruber Softwareentwicklung LDAP Account Manager before 62022-05-14
OSV
CVE-2018-8763: Roland Gruber Softwareentwicklung LDAP Account Manager before 62018-03-27

📋Vendor Advisories

1
Debian
CVE-2018-8763: ldap-account-manager - Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via th...2018

💬Community

1
Bugzilla
CVE-2018-20217 krb5: Reachable assertion in the KDC using S4U2Self requests2019-01-10