Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27895

Опубликовано: 18 мар. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user.

EPSS

Процентиль: 19%
0.00062
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-185

Связанные уязвимости

CVSS3: 4.3
ubuntu
13 дней назад

(LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. ...)

CVSS3: 4.3
debian
13 дней назад

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. ...

EPSS

Процентиль: 19%
0.00062
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-185