CVE-2024-48933
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-48933 is a cross-site scripting (XSS) vulnerability affecting LemonLDAP::NG versions prior to 2.19.3. This issue allows remote attackers to inject arbitrary web scripts or HTML into the login page by exploiting a vulnerability in the user input validation for usernames. If the userControl setting has been configured to allow special HTML characters, an attacker can successfully execute the attack. This vulnerability poses a significant risk as it can lead to the theft of user credentials or other sensitive data. Users are strongly encouraged to upgrade to the latest version of LemonLDAP::NG to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.