Cross-Site Scripting Vulnerability in LemonLDAP::NG Portal
CVE-2025-31510
7.2HIGH
What is CVE-2025-31510?
A vulnerability exists in the LemonLDAP::NG portal prior to version 2.21.0 that enables attackers to perform cross-site scripting (XSS) attacks. By manipulating the tab parameter, remote adversaries can inject arbitrary web scripts or HTML into the login page, potentially compromising user credentials and session data. This vulnerability underscores the necessity for robust input validation and security measures to safeguard web applications from such exploits.
Affected Version(s)
LemonLDAP::NG 2.0.8 < 2.16.5
LemonLDAP::NG 2.17.0 < 2.21.0
