CVE-2012-1115 describes a Cross-Site Scripting (XSS) vulnerability in LDAP Account Manager (LAM) Pro 3.6, specifically within the export, add_value_form, and dn parameters of cmd.php. This flaw affects various distributions including Debian and Fedora, impacting users of LAM. With a CVSS score of 6.1 (Medium), this vulnerability can be exploited remotely with low attack complexity, requiring user interaction (e.g., clicking a malicious link). Successful exploitation could lead to limited confidentiality and integrity impacts, such as session hijacking or defacement. There is no evidence of active exploitation, nor are there known Metasploit modules, Nuclei templates, or ExploitDB entries. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.6CPE matchmatch criteria | cpe:2.3:a:ldap-account-manager:ldap_account_manager:3.6:*:*:*:pro:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
16CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:* | ||
17CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.