Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ledgersmb | Ledgersmb | 1.2.0 (including) | 1.2.0 (including) |
Ledgersmb | Ledgersmb | 1.2.1 (including) | 1.2.1 (including) |
Ledgersmb | Ledgersmb | 1.2.2 (including) | 1.2.2 (including) |
Ledgersmb | Ledgersmb | 1.2.3 (including) | 1.2.3 (including) |
Ledgersmb | Ledgersmb | 1.2.4 (including) | 1.2.4 (including) |
Ledgersmb | Ledgersmb | 1.2.5 (including) | 1.2.5 (including) |
Ledgersmb | Ledgersmb | 1.2.6 (including) | 1.2.6 (including) |