Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3694

Опубликовано: 23 авг. 2021
Источник: debian

Описание

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ledgersmbfixed1.6.9+ds-2.1package

Примечания

  • https://ledgersmb.org/cve-2021-3694-cross-site-scripting

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 4 лет назад

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

CVSS3: 8.2
nvd
больше 4 лет назад

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

github
больше 3 лет назад

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.