CVE Database
/

CVE-2024-9101

Back to search

CVE-2024-9101

Published: Dec 19, 2024

Modified: Dec 20, 2024

PUBLISHED

Description

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

VendorProductVersions

phpLDAPadmin

phpLDAPadmin

affected
1.2.1
affected
1.2.6.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now