CVE-2025-58174: LAM profile editor stored cross-site scripting vulnerability
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stored cross-site scripting in the Profile section via the profile name field, which renders untrusted input as HTML and executes a supplied script (for example a script element). An authenticated user with permission to create or edit a profile can insert a script payload into the profile name and have it executed when the profile data is viewed in a browser. This issue is fixed in version 9.3. No known workarounds are mentioned.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58174?
CVE-2025-58174 is considered a medium severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2025-58174?
To fix CVE-2025-58174, upgrade to LDAP Account Manager version 9.3 or later.
What type of vulnerability is CVE-2025-58174?
CVE-2025-58174 is classified as a stored cross-site scripting (XSS) vulnerability.
Which versions of LDAP Account Manager are affected by CVE-2025-58174?
LDAP Account Manager versions prior to 9.3 are affected by CVE-2025-58174.
What impact does CVE-2025-58174 have on users?
CVE-2025-58174 could allow attackers to execute malicious scripts in the context of a user's session.