Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3693

Опубликовано: 23 авг. 2021
Источник: debian
EPSS Низкий

Описание

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ledgersmbfixed1.6.9+ds-2.1package

Примечания

  • https://ledgersmb.org/cve-2021-3693-cross-site-scripting

EPSS

Процентиль: 73%
0.00792
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

CVSS3: 8.8
nvd
больше 4 лет назад

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

github
больше 3 лет назад

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

EPSS

Процентиль: 73%
0.00792
Низкий