{"id":"CVE-2020-35132","details":"An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.","modified":"2026-07-07T08:50:45.395332313Z","published":"2020-12-11T05:15:12.950Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"32"},{"last_affected":"32"},{"introduced":"33"},{"last_affected":"33"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XA42XDSUPCOXL5ZCP5RGD3FD4JQQWNX/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6PZH3EY2T66N2MGOA7DWCAIVYIJH4BC/"},{"type":"REPORT","url":"https://bugs.launchpad.net/ubuntu/+source/phpldapadmin/+bug/1906474"},{"type":"REPORT","url":"https://github.com/leenooks/phpLDAPadmin/issues/130"},{"type":"FIX","url":"https://github.com/leenooks/phpLDAPadmin/commit/c87571f6b7be15d5cd8b26381b6eb31ad03d28e2"},{"type":"FIX","url":"https://github.com/leenooks/phpLDAPadmin/compare/1.2.5...1.2.6.2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/leenooks/phpldapadmin","events":[{"introduced":"0"},{"fixed":"a8fe6f32743d9db7a0de38fa21d71e61ae0b6a52"},{"fixed":"c87571f6b7be15d5cd8b26381b6eb31ad03d28e2"}],"database_specific":{"cpe":"cpe:2.3:a:phpldapadmin_project:phpldapadmin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.2.6.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.2.4","1.2.6.1","1.2.6","1.2.5","RELEASE-1.2.3","1.2.3","RELEASE-1.2.2","RELEASE-1.2.1.1","RELEASE-1.2.1","RELEASE-1.2.0.5","RELEASE-1.2.0.4","RELEASE-1.2.0.3","RELEASE-1.2.0.2","RELEASE-1.2.0.1","RELEASE-1.2.0","RELEASE-1.2.0-rc1","RELEASE-1.1.0.7","RELEASE-0.9.7.2","RELEASE-1.1.0.6","RELEASE-1.1.0.5","RELEASE-1.1.0.4","RELEASE-1.1.0.3","RELEASE-1.1.0.2","RELEASE-1.1.0.1","RELEASE-1.1.0","RELEASE-1.0.0","RELEASE-0.9.8.1","RELEASE-0.9.8","RELEASE-0.9.7.1","RELEASE-0.9.7","RELEASE-0.9.5","RELEASE-0.9.3","RELEASE-0.9.2","RELEASE-0.9.1","RELEASE-0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-35132.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}