7.5
CVSSv3

CVE-2023-41580

Published: 02/10/2023 Updated: 06/10/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Phpipam before v1.5.2 exists to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows malicious users to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpipam phpipam