The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length.
CVSS Vector
AV:N/AC:L/Au:N/C:N/I:N/A:CLedgersmb
APPLedgersmb< 1.2.15Sql Ledger
APPSql-Ledger≤ 2.8.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References
Related vulnerabilities
CVE-2018-9246CRITICAL9.8PL ✓same product
Command injection w PGObject::Util::DBAdmin — wstrzyknięcie kodu powłoki
CVE-2024-23831HIGH7.5same product
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an a...
CVE-2021-3693HIGH8.8same product
LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially cr...
CVE-2021-3694HIGH8.2same product
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted...
CVE-2009-4402HIGH7.5same product
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative o...