CVE-2021-3694
23.08.2021, 13:15
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Vendor | Product | Version |
---|---|---|
ledgersmb | ledgersmb | 1.1.0 ≤ 𝑥 ≤ 1.1.12 |
ledgersmb | ledgersmb | 1.2.0 ≤ 𝑥 ≤ 1.2.26 |
ledgersmb | ledgersmb | 1.3.0 ≤ 𝑥 ≤ 1.3.47 |
ledgersmb | ledgersmb | 1.4.0 ≤ 𝑥 ≤ 1.4.42 |
ledgersmb | ledgersmb | 1.5.0 ≤ 𝑥 ≤ 1.5.30 |
ledgersmb | ledgersmb | 1.6.0 ≤ 𝑥 ≤ 1.6.33 |
ledgersmb | ledgersmb | 1.7.0 ≤ 𝑥 ≤ 1.7.32 |
ledgersmb | ledgersmb | 1.8.0 ≤ 𝑥 ≤ 1.8.17 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References