CVE-2024-9101

LOW

phpLDAPadmin <1.2.6.7 - XSS

Title source: llm
STIX 2.1

Description

A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set.

Scores

CVSS v4 2.1
EPSS 0.0031
EPSS Percentile 54.5%
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
phpLDAPadmin/phpLDAPadmin 1.2.1
phpLDAPadmin/phpLDAPadmin 1.2.6.7
Published Dec 19, 2024
Tracked Since Feb 18, 2026