PT-2023-3437 · WordPress · Active Directory Integration / Ldap Integration

Andreas Krüger

+1

·

Publicado

2023-06-28

·

Atualizado

2023-07-07

·

CVE-2023-3447

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Active Directory Integration / LDAP Integration plugin for WordPress versions up to, and including, 4.1.5
Description The issue is related to insufficient escaping on the supplied username value, which makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory. This is due to the plugin's failure to properly neutralize special elements in the LDAP query when processing the username parameter.
Recommendations For versions up to, and including, 4.1.5, update to a version that properly escapes the username value to prevent LDAP injection attacks. As a temporary workaround, consider restricting access to the LDAP directory or implementing additional security measures to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03619
CVE-2023-3447

Produtos afetados

Active Directory Integration / Ldap Integration