CVE-2024-52947: XSS
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52947?
CVE-2024-52947 is categorized as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-52947?
To remediate CVE-2024-52947, update LemonLDAP::NG to version 2.20.1 or later and disable the 'Upgrade session' plugin if it is not needed.
Who is affected by CVE-2024-52947?
CVE-2024-52947 affects all versions of LemonLDAP::NG prior to 2.20.1 when the 'Upgrade session' plugin is enabled.
What types of attacks can exploit CVE-2024-52947?
CVE-2024-52947 allows attackers to inject arbitrary web scripts or HTML, potentially leading to account hijacking or data theft.
How can I determine if my LemonLDAP::NG installation is vulnerable to CVE-2024-52947?
If you are using LemonLDAP::NG version prior to 2.20.1 with the 'Upgrade session' plugin enabled, your installation is vulnerable to CVE-2024-52947.