CVE-2021-3693
23.08.2021, 13:15
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
| Vendor | Product | Version |
|---|---|---|
| ledgersmb | ledgersmb | 1.5.0 ≤ 𝑥 ≤ 1.5.30 |
| ledgersmb | ledgersmb | 1.6.0 ≤ 𝑥 ≤ 1.6.33 |
| ledgersmb | ledgersmb | 1.7.0 ≤ 𝑥 ≤ 1.7.32 |
| ledgersmb | ledgersmb | 1.8.0 ≤ 𝑥 ≤ 1.8.17 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References