Search CVE reports
1 – 5 of 5 results
Some fixes available 4 of 6
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a...
1 affected package
ledgersmb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ledgersmb | Fixed | Fixed | Fixed | Not affected |
Some fixes available 4 of 10
LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an...
1 affected package
ledgersmb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ledgersmb | Fixed | Fixed | Fixed | Not affected |
Some fixes available 4 of 8
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
1 affected package
ledgersmb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ledgersmb | Not affected | Not affected | Fixed | Fixed |
Some fixes available 3 of 7
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
1 affected package
ledgersmb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ledgersmb | Not affected | Not affected | Fixed | Fixed |
Some fixes available 7 of 12
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
1 affected package
ledgersmb
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ledgersmb | Fixed | Fixed | Fixed | Fixed |