PT-2018-15325 · Barracuda · Barracuda Message Archiver

Benjamin K.M

·

Published

2018-12-23

·

Updated

2019-01-15

·

CVE-2018-20369

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Barracuda Message Archiver version 2018
Description The issue concerns an XSS vulnerability in the error msg exception-handling value for the ldap user parameter to the cgi-mod/ldap load entry.cgi module. The injection point of the issue is the Add Update module.
Recommendations For Barracuda Message Archiver version 2018, consider restricting access to the cgi-mod/ldap load entry.cgi module until a fix is available, and avoid using the ldap user parameter in this module to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20369

Affected Products

Barracuda Message Archiver