{"id":"CVE-2025-31510","details":"In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.","modified":"2026-08-12T03:51:39.813230033Z","published":"2026-01-16T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/31xxx/CVE-2025-31510.json","cna_assigner":"mitre","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00017.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/31xxx/CVE-2025-31510.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31510"},{"type":"REPORT","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3341"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng","events":[{"introduced":"062e236b9720205e4dd6d268c5a1b916fd177e85"},{"fixed":"9565ce47333ab7a37b34126ce2d378e280e1765a"},{"introduced":"90a97ab1d90f1d32eaf56d0e4f3a72ca7cb40877"},{"fixed":"1421ad73acd3ee3b018db400195611de80dd4b60"}],"database_specific":{"extracted_events":[{"introduced":"2.0.8"},{"fixed":"2.16.5"},{"introduced":"2.17.0"},{"fixed":"2.21.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.16.4","v2.20.0","v2.19.0","v2.16.3","v2.18.1","v2.18.0","v2.0.11","ubuntu/hirsute","debian/bullseye","v2.17.0","v2.16.2","v2.16.1","debian/bookworm","v2.0.15.1","v2.0.15","v2.0.14","v2.0.13","ubuntu/jammy","v2.0.12","v2.0.10","v2.0.9","v2.0.8","ubuntu/groovy"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31510.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}