CVE-2018-8764
27.03.2018, 16:29
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
Vendor | Product | Version |
---|---|---|
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
ldap-account-manager | ldap_account_manager | 𝑥 < 6.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References