CVE-2007-1923 Affecting sql-ledger package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
1.58% (88th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-SQLLEDGER-287673
  • published10 Apr 2007
  • disclosed10 Apr 2007

Introduced: 10 Apr 2007

CVE-2007-1923  (opens in a new tab)

How to fix?

There is no fixed version for Debian:10 sql-ledger.

NVD Description

Note: Versions mentioned in the description apply only to the upstream sql-ledger package and not the sql-ledger package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.

CVSS Scores

version 3.1