PT-2021-21414 · Ledgersmb+2 · Ledgersmb+2

Ehuon

+1

·

Published

2021-08-23

·

Updated

2025-07-17

·

CVE-2021-3694

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LedgerSMB (affected versions not specified)
Description The issue arises from insufficient HTML-encoding of error messages sent to the browser. This can be exploited by sending a specially crafted URL to an authenticated user, potentially leading to remote code execution and information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-3694
DSA-4962-1
DSA-4962-2
USN-5097-1
USN-7647-1

Affected Products

Ledgersmb
Linuxmint
Ubuntu