QID 730468

Date Published: 2022-05-02

QID 730468: LDAP Account Manager Stored Cross-Site Scripting (XSS) and Arbitrary Image Read Vulnerability

LDAP Account Manager is a web application for managing various account types in an LDAP directory.

CVE-2022-24851 : The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks.

Affected Versions:
LDAP Account Manager versions prior to 7.9.1

QID Detection Logic (Unauthenticated):
QID checks for vulnerable version of LDAP Account Manager by sending GET request to web root.

Successful exploitation of this vulnerability may allow an authenticated attacker to steal sensitive data of the targeted user using XSS attack.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to refer to LDAP Account Manager Advisory for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 730468

    Software Advisories
    Advisory ID Software Component Link
    LDAP Account Manager Advisory URL Logo github.com/LDAPAccountManager/lam/security/advisories/GHSA-f2fr-cccr-583v