5.4
CVSSv3

CVE-2020-35132

Published: 11/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An XSS issue has been discovered in phpLDAPadmin prior to 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpldapadmin project phpldapadmin

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #987355 CVE-2020-35132 Package: phpldapadmin; Maintainer for phpldapadmin is Fabio Tranchitella <kobold@debianorg>; Source for phpldapadmin is src:phpldapadmin (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 22 Apr 2021 09:15:01 UTC Severity: important Tags ...
A cross-site scripting issue has been discovered in phpLDAPadmin before 125 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/functionphp ...