{"id":"CVE-2018-8764","details":"Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.","modified":"2026-07-08T05:54:39.300484582Z","published":"2018-03-27T16:29:00.717Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4165"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/146858/LDAP-Account-Manager-6.2-Cross-Site-Scripting.html"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2018/Mar/45"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ldapaccountmanager/lam","events":[{"introduced":"0"},{"fixed":"fe1547e145b06e55048d8385e03ea41df24bf421"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:ldap-account-manager:ldap_account_manager:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.3"}]}}],"versions":["lam_6_3_RC1","lam_6_2","lam_6_2_RC1","lam_6_1","lam_6_1_RC1","lam_6_0","lam_6_0_RC2","lam_6_0_RC1","lam_5_7","lam_5_7_RC1","lam_5_6","lam_5_6_RC1","lam_5_5","lam_5_5_RC1","lam_5_4","lam_5_4_RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8764.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}