Vulnerability Description
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ldap-Account-Manager | Ldap Account Manager | 4.2.1 |
Related Weaknesses (CWE)
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726976
- http://osvdb.org/98828
- http://seclists.org/oss-sec/2013/q4/149Patch
- http://secunia.com/advisories/55413Vendor Advisory
- http://sourceforge.net/p/lam/bugs/156Patch
- http://www.rusty-ice.de/advisory/advisory_2013001.txtPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88203
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726976
- http://osvdb.org/98828
- http://seclists.org/oss-sec/2013/q4/149Patch
- http://secunia.com/advisories/55413Vendor Advisory
- http://sourceforge.net/p/lam/bugs/156Patch
- http://www.rusty-ice.de/advisory/advisory_2013001.txtPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88203
FAQ
What is CVE-2013-4453?
CVE-2013-4453 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
How severe is CVE-2013-4453?
CVE-2013-4453 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4453?
Check the references section above for vendor advisories and patch information. Affected products include: Ldap-Account-Manager Ldap Account Manager.