CVE-2020-35132 - log back

CVE-2020-35132 edited at 18 Mar 2021 12:31:45
References
+ https://github.com/leenooks/phpLDAPadmin/issues/137
https://github.com/leenooks/phpLDAPadmin/issues/130
CVE-2020-35132 edited at 21 Dec 2020 12:54:45
Description
- A cross-site scripting issue has been discovered in phpLDAPadmin before 1.2.5 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
+ A cross-site scripting issue has been discovered in phpLDAPadmin that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
References
https://github.com/leenooks/phpLDAPadmin/issues/130
- https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2
CVE-2020-35132 edited at 11 Dec 2020 13:19:47
Description
- A cross-site scripting issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
+ A cross-site scripting issue has been discovered in phpLDAPadmin before 1.2.5 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
CVE-2020-35132 edited at 11 Dec 2020 13:18:31
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ A cross-site scripting issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
References
+ https://github.com/leenooks/phpLDAPadmin/issues/130
+ https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2
Notes
CVE-2020-35132 created at 11 Dec 2020 13:17:00