Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
{ "binaries": [ { "binary_version": "5.2-1ubuntu1", "binary_name": "ldap-account-manager" }, { "binary_version": "5.2-1ubuntu1", "binary_name": "ldap-account-manager-lamdaemon" } ] }
{ "binaries": [ { "binary_version": "6.2-1", "binary_name": "ldap-account-manager" }, { "binary_version": "6.2-1", "binary_name": "ldap-account-manager-lamdaemon" } ] }