PT-2024-33281 · Unknown · Lemonldap::Ng

Published

2024-10-09

·

Updated

2024-11-30

·

CVE-2024-48933

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LemonLDAP::NG versions prior to 2.19.3
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.
Recommendations For versions prior to 2.19.3, update to version 2.19.3 or later to resolve the issue. As a temporary workaround, consider restricting the userControl settings to prevent the use of special HTML characters in usernames until a patch is applied. Avoid using the username field in a way that allows special HTML characters to be injected into the login page until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-48933
DLA-3979-1

Affected Products

Lemonldap::Ng