CVE-2021-3693
23.08.2021, 13:15
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Vendor | Product | Version |
---|---|---|
ledgersmb | ledgersmb | 1.5.0 ≤ 𝑥 ≤ 1.5.30 |
ledgersmb | ledgersmb | 1.6.0 ≤ 𝑥 ≤ 1.6.33 |
ledgersmb | ledgersmb | 1.7.0 ≤ 𝑥 ≤ 1.7.32 |
ledgersmb | ledgersmb | 1.8.0 ≤ 𝑥 ≤ 1.8.17 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References