6.8
CVSSv2

CVE-2018-8764

Published: 27/03/2018 Updated: 20/04/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Roland Gruber Softwareentwicklung LDAP Account Manager prior to 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote malicious users to defeat a CSRF protection mechanism by leveraging logging.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 9.0

debian debian linux 8.0

ldap-account-manager ldap account manager

Vendor Advisories

Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories CVE-2018-8763 The found Reflected Cross Site Scripting (XSS) vulnerability might allow an attacker to execute JavaScript code in the browser of the victim or to redirect her to a malicious website if the victim clicks on a specia ...

Exploits

LDAP Account Manager version 62 suffers from cross site scripting vulnerabilities ...