Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27895

Опубликовано: 18 мар. 2026
Источник: nvd
CVSS3: 4.3
CVSS3: 8.8
EPSS Низкий

Описание

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ldap-account-manager:ldap_account_manager:*:*:*:*:*:*:*:*
Версия от 8.5 (включая) до 9.5 (исключая)

EPSS

Процентиль: 34%
0.00419
Низкий

4.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-185

Связанные уязвимости

CVSS3: 4.3
ubuntu
5 месяцев назад

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

CVSS3: 4.3
debian
5 месяцев назад

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. ...

EPSS

Процентиль: 34%
0.00419
Низкий

4.3 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-185