Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PLedgersmb
APPLedgersmb1.0.01.1.01.1.11.1.5≤ 1.1.8Sql Ledger
APPSql-Ledger2.4.102.4.112.4.122.4.132.4.142.4.152.4.162.4.42.4.52.4.62.4.72.4.82.4.92.6.02.6.1+ 20 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2018-9246CRITICAL9.8PL ✓same product
Command injection w PGObject::Util::DBAdmin — wstrzyknięcie kodu powłoki
CVE-2024-23831HIGH7.5same product
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an a...
CVE-2021-3693HIGH8.8same product
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially cr...
CVE-2021-3694HIGH8.2same product
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted...
CVE-2009-4402HIGH7.5same product
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative o...