NA

CVE-2020-17477

Published: 26/10/2023 Updated: 16/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school prior to 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a teacher can gain administrator access via an NTLM hash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

univention ucs\\@school