CVE-2023-23749
Last modified
CVE-2023-23749 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Miniorange | Ldap Integration With Active Directory And Openldap | 5.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23749?
How severe is CVE-2023-23749?
How do I fix CVE-2023-23749?
Are you affected by CVE-2023-23749?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
