← back
CVE-2024-9101

phpLDAPadmin: Reflected Cross-Site Scripting in entry_chooser.php

CVSS 2.1 LOWEPSS 0.5%CWE-79
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →