LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
| Software | From | Fixed in |
|---|---|---|
| ledgersmb / ledgersmb | 1.8.0 | 1.8.17.x |
| ledgersmb / ledgersmb | 1.7.0 | 1.7.32.x |
| ledgersmb / ledgersmb | 1.6.0 | 1.6.33.x |
| ledgersmb / ledgersmb | 1.5.0 | 1.5.30.x |
| ledgersmb / ledgersmb | 1.4.0 | 1.4.42.x |
| ledgersmb / ledgersmb | 1.3.0 | 1.3.47.x |
| ledgersmb / ledgersmb | 1.2.0 | 1.2.26.x |
| ledgersmb / ledgersmb | 1.1.0 | 1.1.12.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |