CVE-2021-3693
published 2021-08-23CVE-2021-3693: LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can…
PriorityP352critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
3.01%
86.1th percentile
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ledgersmb | < ledgersmb 1.6.9+ds-2.1 (bookworm) | ledgersmb 1.6.9+ds-2.1 (bookworm) |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-2+deb11u2 | 1.6.9+ds-2+deb11u2 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-2.1 | 1.6.9+ds-2.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-1ubuntu0.1 | 1.6.9+ds-1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.33+ds-1ubuntu0.1 | 1.6.33+ds-1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.33+ds-2.1ubuntu0.1 | 1.6.33+ds-2.1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.3.46-1ubuntu0.1~esm1 | 1.3.46-1ubuntu0.1~esm1 |
| ledgersmb | ledgersmb | >= 0 < 1.4.42+ds-1ubuntu0.1~esm1 | 1.4.42+ds-1ubuntu0.1~esm1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-1ubuntu0.1+esm1 | 1.6.9+ds-1ubuntu0.1+esm1 |
| ledgersmb | ledgersmb | 1.5.0 – 1.5.30 | — |
| ledgersmb | ledgersmb | 1.6.0 – 1.6.33 | — |
| ledgersmb | ledgersmb | 1.7.0 – 1.7.32 | — |
| ledgersmb | ledgersmb | 1.8.0 – 1.8.17 | — |
| ledgersmb | ledgersmb_ledgersmb | >= unspecified < 1.8.18 | 1.8.18 |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.6CRITICAL
vendor_debian8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ledgersmb vulnerabilities
osv·2025-07-17·CVSS 9.6
CVE-2021-3693 [CRITICAL] ledgersmb vulnerabilities
ledgersmb vulnerabilities
It was discovered that LedgerSMB did not check the origin of HTML
fragments. An attacker could possibly use this issue to send a
maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2021-3693)
It was discovered that LedgerSMB did not properly encode HTML
error messages. An attacker could possibly use this issue to send
a maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2021-3694)
It was discovered that LedgerSMB did not guard against discrete
link redirections. An attacker could possibly use this issue to
obtain sensitive information. Th
GHSA
GHSA-x27f-prq2-qwh6: LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM
ghsa_unreviewed·2022-05-24
CVE-2021-3693 [CRITICAL] CWE-79 GHSA-x27f-prq2-qwh6: LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
OSV
ledgersmb vulnerabilities
osv·2021-09-30·CVSS 9.6
CVE-2021-3693 [CRITICAL] ledgersmb vulnerabilities
ledgersmb vulnerabilities
It was discovered that LedgerSMB incorrectly handled certain inputs. An
attacker could use this to leak sensitive information, cause a DoS, or
execute arbitrary code. (CVE-2021-3693, CVE-2021-3694, CVE-2021-3731)
OSV
CVE-2021-3693: LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM
osv·2021-08-23·CVSS 9.6
CVE-2021-3693 [CRITICAL] CVE-2021-3693: LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Ubuntu
LedgerSMB vulnerabilities
vendor_ubuntu·2025-07-17·CVSS 8.8
CVE-2021-3731 [HIGH] LedgerSMB vulnerabilities
Title: LedgerSMB vulnerabilities
Summary: Several security issues were fixed in LedgerSMB.
It was discovered that LedgerSMB did not check the origin of HTML
fragments. An attacker could possibly use this issue to send a
maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2021-3693)
It was discovered that LedgerSMB did not properly encode HTML
error messages. An attacker could possibly use this issue to send
a maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2021-3694)
It was discovered that LedgerSMB did not guard against discrete
link redirections. An attacker
Ubuntu
LedgerSMB vulnerabilities
vendor_ubuntu·2021-09-30·CVSS 8.8
CVE-2021-3693 [HIGH] LedgerSMB vulnerabilities
Title: LedgerSMB vulnerabilities
Summary: ledgersmb could be made to crash if it received specially crafted
input.
It was discovered that LedgerSMB incorrectly handled certain inputs. An
attacker could use this to leak sensitive information, cause a DoS, or
execute arbitrary code. (CVE-2021-3693, CVE-2021-3694, CVE-2021-3731)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3693: ledgersmb - LedgerSMB does not check the origin of HTML fragments merged into the browser's ...
vendor_debian·2021·CVSS 8.8
CVE-2021-3693 [HIGH] CVE-2021-3693: ledgersmb - LedgerSMB does not check the origin of HTML fragments merged into the browser's ...
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Scope: local
bookworm: resolved (fixed in 1.6.9+ds-2.1)
bullseye: resolved (fixed in 1.6.9+ds-2+deb11u2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://huntr.dev/bounties/daf1384d-648a-43fd-9b35-5c37d8ead667https://ledgersmb.org/cve-2021-3693-cross-site-scriptinghttps://www.debian.org/security/2021/dsa-4962https://huntr.dev/bounties/daf1384d-648a-43fd-9b35-5c37d8ead667https://ledgersmb.org/cve-2021-3693-cross-site-scriptinghttps://www.debian.org/security/2021/dsa-4962
2021-08-23
Published