CVE List

CVE-2021-3694

Severe 9.6

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

Published August 23, 2021.

Affected software

Get alerts for Debian Debian Linux

Reference links