Back to search
CVE-2024-9101
Published: Dec 19, 2024
Modified: Dec 20, 2024
PUBLISHED
Description
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.
| Vendor | Product | Versions |
|---|---|---|
phpLDAPadmin | phpLDAPadmin | affected 1.2.1affected 1.2.6.7 |
Weaknesses (CWE)
References
https://www.redguard.ch/blog/2024/12/19/security-advisory-phpldapadmin/
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now