PT-2020-17263 · Phpldapadmin+1 · Phpldapadmin+1

4Ndyguo

·

Published

2020-12-11

·

Updated

2023-07-05

·

CVE-2020-35132

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpLDAPadmin versions prior to 1.2.6.2
Description A cross-site scripting (XSS) issue has been found that allows users to store malicious values, which may be executed by other users at a later time. This issue is related to the get request in lib/function.php.
Recommendations For versions prior to 1.2.6.2, update to version 1.2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the get request function in lib/function.php until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1681
ALT-PU-2023-1818
ALT-PU-2023-4103
CVE-2020-35132
MGASA-2021-0080

Affected Products

Alt Linux
Phpldapadmin