Back

LOW

phpLDAPadmin: Reflected Cross-Site Scripting in entry_chooser.php

Published Dec 19, 2024

Description

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

Affected products

Remediation

Vendor solution

It is recommended to avoid using the eval() function, especially in combination with user-supplied input. Instead of using eval(), it is advised to access the DOM element directly in a safe manner.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner NCSC.ch
Published Dec 19, 2024
Updated Dec 20, 2024
Reserved Sep 23, 2024

CISA Vulnrichment

Updated Dec 20, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner NCSC.ch
Published Dec 19, 2024
Updated Dec 20, 2024

GitHub

No data