cbcvebase.
CVE-2021-3693
published 2021-08-23

CVE-2021-3693: LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can…

PriorityP352critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
3.01%
86.1th percentile
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianledgersmb< ledgersmb 1.6.9+ds-2.1 (bookworm)ledgersmb 1.6.9+ds-2.1 (bookworm)
ledgersmbledgersmb>= 0 < 1.6.9+ds-2+deb11u21.6.9+ds-2+deb11u2
ledgersmbledgersmb>= 0 < 1.6.9+ds-2.11.6.9+ds-2.1
ledgersmbledgersmb>= 0 < 1.6.9+ds-1ubuntu0.11.6.9+ds-1ubuntu0.1
ledgersmbledgersmb>= 0 < 1.6.33+ds-1ubuntu0.11.6.33+ds-1ubuntu0.1
ledgersmbledgersmb>= 0 < 1.6.33+ds-2.1ubuntu0.11.6.33+ds-2.1ubuntu0.1
ledgersmbledgersmb>= 0 < 1.3.46-1ubuntu0.1~esm11.3.46-1ubuntu0.1~esm1
ledgersmbledgersmb>= 0 < 1.4.42+ds-1ubuntu0.1~esm11.4.42+ds-1ubuntu0.1~esm1
ledgersmbledgersmb>= 0 < 1.6.9+ds-1ubuntu0.1+esm11.6.9+ds-1ubuntu0.1+esm1
ledgersmbledgersmb1.5.0 – 1.5.30
ledgersmbledgersmb1.6.0 – 1.6.33
ledgersmbledgersmb1.7.0 – 1.7.32
ledgersmbledgersmb1.8.0 – 1.8.17
ledgersmbledgersmb_ledgersmb>= unspecified < 1.8.181.8.18

CVSS provenance

nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.6CRITICAL
vendor_debian8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.