CVE-2020-35132

NameCVE-2020-35132
DescriptionAn XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesELA-502-1
Debian Bugs987355

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
phpldapadmin (PTS)jessie, jessie (lts)1.2.2-5.2+deb8u3fixed
bookworm1.2.6.3-0.3+deb12u1fixed
sid, trixie1.2.6.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
phpldapadminsourcejessie1.2.2-5.2+deb8u2ELA-502-1
phpldapadminsource(unstable)1.2.6.3-0.3987355

Notes

https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1906474
https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2
https://github.com/leenooks/phpLDAPadmin/issues/130
Fix is incomplete: https://github.com/leenooks/phpLDAPadmin/issues/130#issuecomment-745152260
https://github.com/leenooks/phpLDAPadmin/issues/137

Search for package or bug name: Reporting problems