← Back to CVE List

CVE-2024-9101

Published: 2024-12-19T14:15Z
Last Modified: 2024-12-19T14:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is unsafely passed to the JavaScript 'eval' function. However, exploitation is limited to specific conditions where 'opener' is correctly set. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt