CVE-2018-8763 — Cross-site Scripting in Ldap Account Manager
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 36.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 14
Description
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages2 packages
Also affects: Debian Linux 7.0, 8.0, 9.0
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2018-8763: ldap-account-manager - Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via th...↗2018