CVE-2022-31086
Summary
| CVE | CVE-2022-31086 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-27 21:15:00 UTC |
| Updated | 2022-07-07 14:08:00 UTC |
| Description | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5177-1 ldap-account-manager |
DEBIAN |
www.debian.org |
|
| Merge pull request from GHSA-r387-grjx-qgvw · LDAPAccountManager/lam@f1d5d04 · GitHub |
MISC |
github.com |
|
| Incorrect Regular Expressions · Advisory · LDAPAccountManager/lam · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180808 Debian Security Update for ldap-account-manager (DSA 5177-1)
- 182526 Debian Security Update for ldap-account-manager (CVE-2022-31086)