Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LemonLDAP::NG 安全漏洞
Vulnerability Description
LemonLDAP::NG是LemonLDAP::NG开源的一套Web单点登录和访问管理软件。 LemonLDAP::NG 2.19.3版本之前存在安全漏洞,该漏洞源于如果 userControl 设置为允许特殊 HTML 字符的非默认值,则远程攻击者可以通过用户名将任意 Web 脚本或 HTML 注入登录页面。
CVSS Information
N/A
Vulnerability Type
N/A