Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6mpf-h5jc-fvrw

Опубликовано: 19 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 2.1

Описание

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

EPSS

Процентиль: 55%
0.00325
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

nvd
около 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

debian
около 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Cho ...

CVSS3: 5.8
fstec
около 1 года назад

Уязвимость веб-инструмента администрирования LDAP phpLDAPadmin, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.8
redos
около 1 месяца назад

Уязвимость phpldapadmin

EPSS

Процентиль: 55%
0.00325
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79