VendorsLDAP Account Managerldap_account_managerall versions
Vulnerabilities

LDAP Account Manager (LAM)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2022-31084
Unauthenticated Remote Code Execution in ldap-account-manager
Published 2022-06-27 · Modified
9.0EPSS 0.025
CVE-2022-31086
Incorrect Regular Expressions in ldap-account-manager
Published 2022-06-27 · Modified
8.8EPSS 0.023
CVE-2018-8764
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
Published 2018-03-27 · Modified
8.8EPSS 0.013
CVE-2026-27895
LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
Published 2026-03-17 · Analyzed
8.8EPSS 0.008
CVE-2026-27894
LAM has Authenticated Local File Inclusion (LFI) in PDF export
Published 2026-03-17 · Analyzed
8.8EPSS 0.007
CVE-2022-24851
Stored XSS and path traversal in LDAPAccountManager/lam
Published 2022-04-15 · Modified
8.1EPSS 0.011
CVE-2024-23333
LAM vulnerable to Authenticated Remote Code Execution
Published 2024-03-18 · Analyzed
7.9EPSS 0.179
CVE-2022-31087
Incorrect Default Permissions in ldap-account-manager
Published 2022-06-27 · Modified
7.8EPSS 0.004
CVE-2022-31088
Unauthenticated LDAP Injection in ldap-account-manager
Published 2022-06-27 · Modified
6.5EPSS 0.013
CVE-2012-1114
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
Published 2019-12-05 · Modified
6.1EPSS 0.016
CVE-2012-1115
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
Published 2019-12-05 · Modified
6.1EPSS 0.016
CVE-2018-8763
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
Published 2018-03-27 · Modified
6.1EPSS 0.015
CVE-2022-31085
Missing Encryption of Sensitive Data in ldap-account-manager
Published 2022-06-27 · Modified
6.1EPSS 0.003
CVE-2013-4453
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.
Published 2013-11-05 · Modified
4.3EPSS 0.014