Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31086

Опубликовано: 27 июн. 2022
Источник: nvd
CVSS3: 6.6
CVSS3: 8.8
CVSS2: 6
EPSS Низкий

Описание

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ldap-account-manager:ldap_account_manager:*:*:*:*:*:*:*:*
Версия до 8.0 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01329
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-74
CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.

CVSS3: 8.8
debian
больше 3 лет назад

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. ...

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость веб-приложения управления учетными записями LDAP Account Manager, существует из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 80%
0.01329
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-74
CWE-434