4.3
CVSSv2

CVE-2018-20806

Published: 17/03/2019 Updated: 18/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phamm phamm 0.6.8

Vendor Advisories

Debian Bug report logs - #924731 phamm: CVE-2018-20806: Reflected XSS in Phamm login page Package: src:phamm; Maintainer for src:phamm is Phamm Team <team@phammorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 16 Mar 2019 15:06:01 UTC Severity: grave Tags: security, upstream Found in version ph ...