Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to missing sanitization of inputs in ldap search query. The vulnerability could impact all instances using ldap authentication where a malicious actor had access to a user account. Version 1.45.3 has a patch for the issue.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:LHomarr
APPHomarr< 1.45.3
Related vulnerabilities
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compro...
Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has ...
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the exe...
Homarr to otwartoźródłowy dashboard. Przed wersją 1.57.0 endpoint rejestracji użytkownika (/api/trpc/user.regi...
Homarr jest otwartym pulpitem nawigacyjnym. Przed wersją 1.54.0 endpoint integration.all tRPC w Homarr był nar...