PT-2022-3279 · Unknown · Ldap Account Manager
Arseniy Sharoglazov
·
Published
2022-06-16
·
Updated
2022-07-15
·
CVE-2022-31086
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LDAP Account Manager versions prior to 8.0
Description
The issue arises from incorrect regular expressions in LDAP Account Manager, allowing the upload of PHP scripts to the
/config/templates/pdf/ directory. This could lead to Remote Code Execution if the directory is accessible to remote users, which is not the default configuration. The estimated number of potentially affected devices worldwide is not specified. There are no reported real-world incidents where this issue was exploited. The vulnerability is related to the upload of PHP scripts to the /config/templates/pdf/ directory, which can be accessed remotely if not properly configured.Recommendations
For versions prior to 8.0, update to version 8.0 to resolve the issue.
As a temporary workaround, consider restricting access to the
/config/templates/pdf/ directory to prevent remote users from uploading PHP scripts.Exploit
Fix
RCE
Special Elements Injection
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ldap Account Manager