Логотип exploitDog
bind:CVE-2024-52947
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52947

Количество 4

Количество 4

ubuntu логотип

CVE-2024-52947

около 1 года назад

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-52947

около 1 года назад

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-52947

около 1 года назад

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.2 ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-425w-xhjg-hfcm

около 1 года назад

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-52947

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

CVSS3: 5.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-52947

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

CVSS3: 5.4
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-52947

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.2 ...

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-425w-xhjg-hfcm

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

CVSS3: 5.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу