PT-2023-3437 · WordPress · Active Directory Integration / Ldap Integration
Andreas Krüger
+1
·
Published
2023-06-28
·
Updated
2023-07-07
·
CVE-2023-3447
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Active Directory Integration / LDAP Integration plugin for WordPress versions up to, and including, 4.1.5
Description
The issue is related to insufficient escaping on the supplied
username value, which makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory. This is due to the plugin's failure to properly neutralize special elements in the LDAP query when processing the username parameter.Recommendations
For versions up to, and including, 4.1.5, update to a version that properly escapes the
username value to prevent LDAP injection attacks. As a temporary workaround, consider restricting access to the LDAP directory or implementing additional security measures to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Active Directory Integration / Ldap Integration