VulnerabilityModified
CVE-2020-35132
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
MEDIUM 5.4EPSS 1.25%
Does this matter?
Lower severity and a low EPSS score (1.25%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- phpldapadmin project/phpldapadmin · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1906474Issue Tracking, Third Party Advisory
- https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2Patch, Third Party Advisory
- https://github.com/leenooks/phpLDAPadmin/compare/1.2.5...1.2.6.2Patch, Third Party Advisory
- https://github.com/leenooks/phpLDAPadmin/issues/130Exploit, Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XA42XDSUPCOXL5ZCP5RGD3FD4JQQWNX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6PZH3EY2T66N2MGOA7DWCAIVYIJH4BC/
- https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1906474Issue Tracking, Third Party Advisory
- https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2Patch, Third Party Advisory
- https://github.com/leenooks/phpLDAPadmin/compare/1.2.5...1.2.6.2Patch, Third Party Advisory
- https://github.com/leenooks/phpLDAPadmin/issues/130Exploit, Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XA42XDSUPCOXL5ZCP5RGD3FD4JQQWNX/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6PZH3EY2T66N2MGOA7DWCAIVYIJH4BC/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.