CVE-2024-48933: XSS
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48933?
CVE-2024-48933 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-48933?
To fix CVE-2024-48933, upgrade LemonLDAP::NG to version 2.19.3 or later.
Who is affected by CVE-2024-48933?
CVE-2024-48933 affects versions of LemonLDAP::NG before 2.19.3 configured with userControl allowing special HTML characters.
What kind of attacks can be executed using CVE-2024-48933?
Attackers can exploit CVE-2024-48933 to inject arbitrary web scripts or HTML into the login page, potentially compromising user credentials.
Is CVE-2024-48933 a critical vulnerability?
CVE-2024-48933 is not critical, but it poses significant risks due to cross-site scripting possibilities that can lead to further exploitation.