Vulnerability identifier: #VU65009
Vulnerability risk: Low
CVSSv3.1: 4.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-79
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
LDAP Account Manager
Server applications /
Remote management servers, RDP, SSH
Vendor: LDAP Account Manager
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Note, the vulnerability can be exploited against Internet Explorer users only.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
LDAP Account Manager: 0.4.7 - 7.9.1
External links
http://github.com/LDAPAccountManager/lam/security/advisories/GHSA-6m3q-5c84-6h6j
http://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.