CVE-2018-8763

Source
https://cve.org/CVERecord?id=CVE-2018-8763
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8763.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-8763
Downstream
Published
2018-03-27T16:29:00.653Z
Modified
2026-04-02T01:28:06.861098Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.

References

Affected packages

Git / github.com/ldapaccountmanager/lam

Affected ranges

Type
GIT
Repo
https://github.com/ldapaccountmanager/lam
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "7.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "9.0"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "6.3"
        }
    ]
}

Affected versions

Other
lam_5_4
lam_5_4_RC1
lam_5_5
lam_5_5_RC1
lam_5_6
lam_5_6_RC1
lam_5_7
lam_5_7_RC1
lam_6_0
lam_6_0_1
lam_6_0_RC1
lam_6_0_RC2
lam_6_1
lam_6_1_RC1
lam_6_2
lam_6_2_1
lam_6_2_RC1
lam_6_3_RC1
origin/tags/after_0_6_merge
origin/tags/before_0_6_merge
origin/tags/lam_0_4_10
origin/tags/lam_0_4_7
origin/tags/lam_0_4_8
origin/tags/lam_0_4_9
origin/tags/lam_0_5_0
origin/tags/lam_0_5_1
origin/tags/lam_0_5_2
origin/tags/lam_0_5_3
origin/tags/lam_0_5_alpha1
origin/tags/lam_0_5_alpha2
origin/tags/lam_0_5_rc1
origin/tags/lam_0_5_rc2
origin/tags/lam_0_5_rc3
origin/tags/lam_1_0_0
origin/tags/lam_1_0_1
origin/tags/lam_1_0_2
origin/tags/lam_1_0_3
origin/tags/lam_1_0_4
origin/tags/lam_1_0_4RC1
origin/tags/lam_1_0_rc1
origin/tags/lam_1_0_rc2
origin/tags/lam_1_1_0
origin/tags/lam_1_1_0_RC1
origin/tags/lam_1_1_1
origin/tags/lam_1_1_1_rc1
origin/tags/lam_1_2_0
origin/tags/lam_1_2_0_RC1
origin/tags/lam_1_3_0
origin/tags/lam_1_3_0_RC1
origin/tags/lam_2_0_0
origin/tags/lam_2_0_0_RC1
origin/tags/lam_2_1_0
origin/tags/lam_2_1_0_RC1
origin/tags/lam_2_2_0
origin/tags/lam_2_2_0_RC1
origin/tags/lam_2_3_0
origin/tags/lam_2_3_0RC1
origin/tags/lam_2_4_0
origin/tags/lam_2_5_0
origin/tags/lam_2_5_0_RC1
origin/tags/lam_2_6_0
origin/tags/lam_2_6_0_RC1
origin/tags/lam_2_7_0
origin/tags/lam_2_7_0_RC1
origin/tags/lam_2_8_0
origin/tags/lam_2_8_0_RC1
origin/tags/lam_2_9_0
origin/tags/lam_2_9_0_RC1
origin/tags/lam_3_0_0
origin/tags/lam_3_0_0_RC1
origin/tags/lam_3_1_0
origin/tags/lam_3_1_0_RC1
origin/tags/lam_3_1_1
origin/tags/lam_3_2_0
origin/tags/lam_3_2_0_RC1
origin/tags/lam_3_3_0
origin/tags/lam_3_3_0_RC1
origin/tags/lam_3_4_0
origin/tags/lam_3_4_0_RC1
origin/tags/lam_3_5_0
origin/tags/lam_3_5_0_RC1
origin/tags/lam_3_6
origin/tags/lam_3_6_1
origin/tags/lam_3_6_RC1
origin/tags/lam_3_7
origin/tags/lam_3_7_RC1
origin/tags/lam_3_8
origin/tags/lam_3_8_RC1
origin/tags/lam_3_9
origin/tags/lam_3_9_RC1
origin/tags/lam_4_0
origin/tags/lam_4_0_1
origin/tags/lam_4_0_RC1
origin/tags/lam_4_1_RC1
origin/tags/start
origin/tags/trunk

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8763.json"