Beveiligingsadvies

CVE-2021-3693

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-08-23 12:41:57
Laatst bijgewerkt 2024-08-03 17:01:07
Toegewezen door @huntrdev
CVSS-score 8.8
Status PUBLISHED

Beschrijving

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.