Vulnerabilities > Ledgersmb > Ledgersmb > 1.2.7

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2021-3694 Cross-site Scripting vulnerability in multiple products
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser.
6.8
2021-08-23 CVE-2021-3731 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'.
4.3
2007-10-11 CVE-2007-5372 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the invoice quantity field or (2) the sort field.
network
low complexity
dws-systems-inc ledgersmb CWE-89
critical
10.0