VYPR
High severity8.8NVD Advisory· Published Jun 27, 2022· Updated Jun 17, 2026

CVE-2022-31086

CVE-2022-31086

Description

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:ldap-account-manager:ldap_account_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ldap-account-manager:ldap_account_manager:*:*:*:*:*:*:*:*range: <8.0
    • (no CPE)range: <8.0
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • Ldapaccountmanager/Lamllm-fuzzy2 versions
    <8.0+ 1 more
    • (no CPE)range: <8.0
    • (no CPE)range: < 8.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.