LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
| Software | From | Fixed in |
|---|---|---|
| ledgersmb / ledgersmb | 1.8.0 | 1.8.17.x |
| ledgersmb / ledgersmb | 1.7.0 | 1.7.32.x |
| ledgersmb / ledgersmb | 1.6.0 | 1.6.33.x |
| ledgersmb / ledgersmb | 1.5.0 | 1.5.30.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |