NA

CVE-2023-23749

Published: 17/01/2023 Updated: 27/01/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

miniorange ldap integration with active directory and openldap 5.0.2