PT-2018-15325 · Barracuda · Barracuda Message Archiver
Benjamin K.M
·
Published
2018-12-23
·
Updated
2019-01-15
·
CVE-2018-20369
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Barracuda Message Archiver version 2018
Description
The issue concerns an XSS vulnerability in the error msg exception-handling value for the
ldap user parameter to the cgi-mod/ldap load entry.cgi module. The injection point of the issue is the Add Update module.Recommendations
For Barracuda Message Archiver version 2018, consider restricting access to the
cgi-mod/ldap load entry.cgi module until a fix is available, and avoid using the ldap user parameter in this module to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barracuda Message Archiver