CVE-2025-31510: XSS
Published Jan 16, 2026
·Updated
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
Affected Software
1 affected component
LemonLDAP::NG<2.21.0
Event History
Jan 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31510?
CVE-2025-31510 is classified as a cross-site scripting (XSS) vulnerability with a high severity rating.
2
How do I fix CVE-2025-31510?
To fix CVE-2025-31510, update LemonLDAP::NG to version 2.21.0 or later.
3
What types of attacks does CVE-2025-31510 facilitate?
CVE-2025-31510 allows remote attackers to inject arbitrary web scripts or HTML into the login page.
4
In which versions of LemonLDAP::NG is CVE-2025-31510 present?
CVE-2025-31510 affects LemonLDAP::NG versions prior to 2.21.0.
5
What is the impact of exploiting CVE-2025-31510?
Exploiting CVE-2025-31510 can lead to session hijacking and unauthorized actions performed on behalf of the user.