Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23749


The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.


Published

2023-01-17T20:15:11.983

Last Modified

2025-04-03T20:15:23.100

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-74
  • Type: Secondary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application miniorange ldap_integration_with_active_directory_and_openldap 5.0.2 Yes

References