CVE-2020-35132Cross-site Scripting in Project Phpldapadmin

Severity
5.4MEDIUMNVD
EPSS
0.5%
top 33.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 24

Description

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages3 packages

debiandebian/phpldapadmin< phpldapadmin 1.2.6.3-0.3 (bookworm)
Debianphpldapadmin_project/phpldapadmin< 1.2.6.3-0.3+2

Also affects: Fedora 32, 33

Patches

🔴Vulnerability Details

2
GHSA
GHSA-44vj-36hg-g8rr: An XSS issue has been discovered in phpLDAPadmin before 12022-05-24
OSV
CVE-2020-35132: An XSS issue has been discovered in phpLDAPadmin before 12020-12-11

📋Vendor Advisories

1
Debian
CVE-2020-35132: phpldapadmin - An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows user...2020