Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2021-3694

Published: 23 August 2021

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.

Priority

Medium

Cvss 3 Severity Score

9.6

Score breakdown

Status

Package Release Status
ledgersmb
Launchpad, Ubuntu, Debian
focal
Released (1.6.9+ds-1ubuntu0.1)
hirsute
Released (1.6.9+ds-2ubuntu0.1)
jammy Needs triage

bionic Needs triage

trusty Does not exist

upstream Needs triage

kinetic Ignored
(end of life, was needs-triage)
impish Ignored
(end of life)
xenial Needs triage

lunar Needs triage

mantic Needs triage

Severity score breakdown

Parameter Value
Base score 9.6
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Changed
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H