LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5177-1 ldap-account-manager security update
EUVD EUVD EUVD-2022-52743 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00364}

epss

{'score': 0.01329}


Wed, 23 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-23T18:07:11.602Z

Reserved: 2022-05-18T00:00:00.000Z

Link: CVE-2022-31086

cve-icon Vulnrichment

Updated: 2024-08-03T07:11:39.584Z

cve-icon NVD

Status : Modified

Published: 2022-06-27T21:15:08.280

Modified: 2024-11-21T07:03:51.990

Link: CVE-2022-31086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.