Description


The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

Weaknesses



CWE-74

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-74

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-17T19:15:11.983Z

3 years ago

Last modified

2025-04-03T18:15:23.100Z

11 months ago