Описание
Cross-site scripting (XSS) vulnerability in OpenLD before 1.1.9, and 1.1-modified before 1.1-modified3, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the Search feature, possibly the term parameter.
Ссылки
- Vendor Advisory
- Patch
- PatchURL Repurposed
- PatchURL Repurposed
- Patch
- Vendor Advisory
- Patch
- PatchURL Repurposed
- PatchURL Repurposed
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.8 (включая)Версия до 1.1_modified2 (включая)
Одно из
cpe:2.3:a:openld:openld:*:*:*:*:*:*:*:*
cpe:2.3:a:openld:openld:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00537
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in OpenLD before 1.1.9, and 1.1-modified before 1.1-modified3, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the Search feature, possibly the term parameter.
EPSS
Процентиль: 67%
0.00537
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other