Related Vulnerabilities: CVE-2020-35132  

A cross-site scripting issue has been discovered in phpLDAPadmin before 1.2.5 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

A cross-site scripting issue has been discovered in phpLDAPadmin before 1.2.5 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

AVG-1346 phpldapadmin 1.2.3-13 1.2.5-1 Medium Fixed

https://github.com/leenooks/phpLDAPadmin/issues/130
https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2