PT-2023-3437 · WordPress · Active Directory Integration / Ldap Integration
Andreas Krüger
+1
·
Publicado
2023-06-28
·
Atualizado
2023-07-07
·
CVE-2023-3447
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Active Directory Integration / LDAP Integration plugin for WordPress versions up to, and including, 4.1.5
Description
The issue is related to insufficient escaping on the supplied
username value, which makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory. This is due to the plugin's failure to properly neutralize special elements in the LDAP query when processing the username parameter.Recommendations
For versions up to, and including, 4.1.5, update to a version that properly escapes the
username value to prevent LDAP injection attacks. As a temporary workaround, consider restricting access to the LDAP directory or implementing additional security measures to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Active Directory Integration / Ldap Integration