CVE-2007-1840

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/04/2007
Last modified:
09/04/2025

Description

lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ldap_account_manager:ldap_account_manager:*:*:*:*:*:*:*:* 1.0_rc2 (including)