Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia 7: MGASA-2021-0080 Moderate: phpLDAPadmin XSS Threat

mageia
Calendar Grey February 11, 2021
Dist Mageia Esm H88
The revamped phpldapadmin distribution tackles a critical XSS vulnerability, enhancing security for Mageia users while mitigating potential malicious threats.
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in l...

Summary

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php (CVE-2020-35132).

References

- https://bugs.mageia.org/show_bug.cgi?id=27905

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6XA42XDSUPCOXL5ZCP5RGD3FD4JQQWNX/

- https://www.cve.org/CVERecord?id=CVE-2020-35132

Resolution

SRPMS

- 7/core/phpldapadmin-1.2.6.2-1.mga7

Publication date: 11 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0080.html
Type: security
CVE: CVE-2020-35132

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here