Back to Database
Status published
High
CVE-2021-3694
Cross-site Scripting (XSS) - Reflected in ledgersmb/ledgersmb
Vulnerability Description
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3694
Credits & Attribution
No credits recorded in the NVD database.
References
More from ledgersmb
View All →CVE-2024-23831
Privilege escalation through CSRF attack on 'setup.pl'
High
7.5
CVE-2021-3882
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb/ledgersmb
Medium
5.9
CVE-2021-3731
Improper Restriction of Rendered UI Layers or Frames in ledgersmb/ledgersmb
Medium
5.9
CVE-2021-3693
Cross-site Scripting (XSS) - DOM in ledgersmb/ledgersmb
High
8.8
CVE-2008-4078
SQL injection vulnerability in the AR/AP transaction report in (1)...
Medium
6.5
Affected Vendor
ledgersmb
View all reports →Affected Software
ledgersmb/ledgersmb
Vulnerable Versions:
1.7.33, unspecified
Timeline
Official Publish:
August 23rd, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N