CVE-2017-11107: XSS
Published Jul 8, 2017
·Updated
phpLDAPadmin through 1.2.3 has XSS in htdocs/entrychooser.php via the form, element, rdn, or container parameter.
Affected Software
2 affected components
Phpldapadmin Project Phpldapadmin<=1.2.3
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jul 8, 2017
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11107?
CVE-2017-11107 is classified as a high severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-11107?
To fix CVE-2017-11107, upgrade phpLDAPadmin to version 1.2.4 or later.
3
Who is affected by CVE-2017-11107?
CVE-2017-11107 affects phpLDAPadmin versions up to and including 1.2.3 and specific Debian Linux installations.
4
What type of vulnerability is CVE-2017-11107?
CVE-2017-11107 is an XSS vulnerability that allows attackers to inject malicious scripts into web pages.
5
What parameters are involved in CVE-2017-11107?
CVE-2017-11107 is triggered via the form, element, rdn, or container parameters in entry_chooser.php.