Vulnerabilities > Ledgersmb > Ledgersmb > 1.4.42

DATE CVE VULNERABILITY TITLE RISK
2024-02-02 CVE-2024-23831 Cross-Site Request Forgery (CSRF) vulnerability in Ledgersmb
LedgerSMB is a free web-based double-entry accounting system.
network
high complexity
ledgersmb CWE-352
7.5
2021-08-23 CVE-2021-3694 Cross-site Scripting vulnerability in multiple products
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser.
6.8
2021-08-23 CVE-2021-3731 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'.
4.3