Description
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1287-1 | New ldap-account-manager packages fix multiple vulnerabilities |
EUVD |
EUVD-2007-1834 | lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS). |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T13:13:41.062Z
Reserved: 2007-04-02T00:00:00.000Z
Link: CVE-2007-1840
No data.
Status : Modified
Published: 2007-04-03T00:19:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-1840
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD