CVE-2021-3731
published 2021-08-23CVE-2021-3731: LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a…
PriorityP421medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
1.11%
62.5th percentile
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ledgersmb | < ledgersmb 1.6.9+ds-2.1 (bookworm) | ledgersmb 1.6.9+ds-2.1 (bookworm) |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-2+deb11u2 | 1.6.9+ds-2+deb11u2 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-2.1 | 1.6.9+ds-2.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-1ubuntu0.1 | 1.6.9+ds-1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.33+ds-1ubuntu0.1 | 1.6.33+ds-1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.33+ds-2.1ubuntu0.1 | 1.6.33+ds-2.1ubuntu0.1 |
| ledgersmb | ledgersmb | >= 0 < 1.3.46-1ubuntu0.1~esm1 | 1.3.46-1ubuntu0.1~esm1 |
| ledgersmb | ledgersmb | >= 0 < 1.4.42+ds-1ubuntu0.1~esm1 | 1.4.42+ds-1ubuntu0.1~esm1 |
| ledgersmb | ledgersmb | >= 0 < 1.6.9+ds-1ubuntu0.1+esm1 | 1.6.9+ds-1ubuntu0.1+esm1 |
| ledgersmb | ledgersmb | 1.1.0 – 1.1.12 | — |
| ledgersmb | ledgersmb | 1.2.0 – 1.2.26 | — |
| ledgersmb | ledgersmb | 1.3.0 – 1.3.47 | — |
| ledgersmb | ledgersmb | 1.4.0 – 1.4.42 | — |
| ledgersmb | ledgersmb | 1.5.0 – 1.5.30 | — |
| ledgersmb | ledgersmb | 1.6.0 – 1.6.33 | — |
| ledgersmb | ledgersmb | 1.7.0 – 1.7.32 | — |
| ledgersmb | ledgersmb | 1.8.0 – 1.8.17 | — |
| ledgersmb | ledgersmb_ledgersmb | >= unspecified < 1.8.18 | 1.8.18 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.6CRITICAL
vendor_ubuntu8.8HIGH
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ledgersmb vulnerabilities
osv·2025-07-17·CVSS 9.6
CVE-2021-3693 [CRITICAL] ledgersmb vulnerabilities
ledgersmb vulnerabilities
It was discovered that LedgerSMB did not check the origin of HTML
fragments. An attacker could possibly use this issue to send a
maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2021-3693)
It was discovered that LedgerSMB did not properly encode HTML
error messages. An attacker could possibly use this issue to send
a maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2021-3694)
It was discovered that LedgerSMB did not guard against discrete
link redirections. An attacker could possibly use this issue to
obtain sensitive information. Th
GHSA
GHSA-vj43-qmpm-3qqp: LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'
ghsa_unreviewed·2022-05-24
CVE-2021-3731 [MEDIUM] CWE-1021 GHSA-vj43-qmpm-3qqp: LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
OSV
ledgersmb vulnerabilities
osv·2021-09-30·CVSS 9.6
CVE-2021-3693 [CRITICAL] ledgersmb vulnerabilities
ledgersmb vulnerabilities
It was discovered that LedgerSMB incorrectly handled certain inputs. An
attacker could use this to leak sensitive information, cause a DoS, or
execute arbitrary code. (CVE-2021-3693, CVE-2021-3694, CVE-2021-3731)
OSV
CVE-2021-3731: LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'
osv·2021-08-23·CVSS 4.7
CVE-2021-3731 [MEDIUM] CVE-2021-3731: LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
Ubuntu
LedgerSMB vulnerabilities
vendor_ubuntu·2025-07-17·CVSS 8.8
CVE-2021-3731 [HIGH] LedgerSMB vulnerabilities
Title: LedgerSMB vulnerabilities
Summary: Several security issues were fixed in LedgerSMB.
It was discovered that LedgerSMB did not check the origin of HTML
fragments. An attacker could possibly use this issue to send a
maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2021-3693)
It was discovered that LedgerSMB did not properly encode HTML
error messages. An attacker could possibly use this issue to send
a maliciously crafted URL to the server and obtain sensitive
information, or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2021-3694)
It was discovered that LedgerSMB did not guard against discrete
link redirections. An attacker
Ubuntu
LedgerSMB vulnerabilities
vendor_ubuntu·2021-09-30·CVSS 8.8
CVE-2021-3693 [HIGH] LedgerSMB vulnerabilities
Title: LedgerSMB vulnerabilities
Summary: ledgersmb could be made to crash if it received specially crafted
input.
It was discovered that LedgerSMB incorrectly handled certain inputs. An
attacker could use this to leak sensitive information, cause a DoS, or
execute arbitrary code. (CVE-2021-3693, CVE-2021-3694, CVE-2021-3731)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3731: ledgersmb - LedgerSMB does not sufficiently guard against being wrapped by other sites, maki...
vendor_debian·2021·CVSS 5.9
CVE-2021-3731 [MEDIUM] CVE-2021-3731: ledgersmb - LedgerSMB does not sufficiently guard against being wrapped by other sites, maki...
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
Scope: local
bookworm: resolved (fixed in 1.6.9+ds-2.1)
bullseye: resolved (fixed in 1.6.9+ds-2+deb11u2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://huntr.dev/bounties/5664331d-f5f8-4412-8566-408f8655888ahttps://ledgersmb.org/cve-2021-3731-clickjackinghttps://www.debian.org/security/2021/dsa-4962https://huntr.dev/bounties/5664331d-f5f8-4412-8566-408f8655888ahttps://ledgersmb.org/cve-2021-3731-clickjackinghttps://www.debian.org/security/2021/dsa-4962
2021-08-23
Published