CVE-2018-20369: Barracuda Message Archiver
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
Affected products
- Barracuda Message Archiver: version 2018 only
Published 2018-12-23. Last modified 2026-06-17.