CVE-2007-1840: XSS
lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1840?
CVE-2007-1840 is classified as a moderate severity vulnerability due to the potential for cross-site scripting (XSS).
How do I fix CVE-2007-1840?
To fix CVE-2007-1840, upgrade LDAP Account Manager to version 1.3.0 or later, which addresses the HTML escaping issue.
What type of vulnerability is CVE-2007-1840?
CVE-2007-1840 is a cross-site scripting (XSS) vulnerability that exploits unescaped HTML special characters in LDAP data.
Which versions of LDAP Account Manager are affected by CVE-2007-1840?
LDAP Account Manager versions prior to 1.3.0, including 1.0.rc2, are affected by CVE-2007-1840.
Can CVE-2007-1840 be exploited remotely?
Yes, CVE-2007-1840 can be exploited remotely, allowing attackers to potentially execute malicious scripts in a user's browser.