PT-2023-3437 · WordPress · Active Directory Integration / Ldap Integration

Andreas Krüger

+1

·

Published

2023-06-28

·

Updated

2023-07-07

·

CVE-2023-3447

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Active Directory Integration / LDAP Integration plugin for WordPress versions up to, and including, 4.1.5
Description The issue is related to insufficient escaping on the supplied username value, which makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory. This is due to the plugin's failure to properly neutralize special elements in the LDAP query when processing the username parameter.
Recommendations For versions up to, and including, 4.1.5, update to a version that properly escapes the username value to prevent LDAP injection attacks. As a temporary workaround, consider restricting access to the LDAP directory or implementing additional security measures to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-03619
CVE-2023-3447

Affected Products

Active Directory Integration / Ldap Integration