Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6mpf-h5jc-fvrw

Опубликовано: 19 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 2.1

Описание

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

EPSS

Процентиль: 53%
0.00302
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

nvd
больше 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

debian
больше 1 года назад

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Cho ...

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость веб-инструмента администрирования LDAP phpLDAPadmin, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.8
redos
4 месяца назад

Уязвимость phpldapadmin

EPSS

Процентиль: 53%
0.00302
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79