#VU65009 Cross-site scripting in LDAP Account Manager


Published: 2022-07-07

Vulnerability identifier: #VU65009

Vulnerability risk: Low

CVSSv3.1: 4.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-31085

CWE-ID: CWE-79

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
LDAP Account Manager
Server applications / Remote management servers, RDP, SSH

Vendor: LDAP Account Manager

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Note, the vulnerability can be exploited against Internet Explorer users only.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

LDAP Account Manager: 0.4.7 - 7.9.1


External links
http://github.com/LDAPAccountManager/lam/security/advisories/GHSA-6m3q-5c84-6h6j
http://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability