CVE-2021-3694
—CVSS 3.1
9.6 critical
EPSS
3%p84
Published
()
Modified
Description
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.
In the news0 stories
No ingested article mentions this CVE yet.