PT-2024-19815 · Unknown+1 · Ldap Account Manager+1

Maik-S

·

Published

2024-03-18

·

Updated

2025-12-23

·

CVE-2024-23333

CVSS v3.1

7.9

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions LDAP Account Manager (LAM) versions prior to 8.7
Description LDAP Account Manager (LAM) is a web frontend for managing entries stored in an LDAP directory. LAM's log configuration allows specifying arbitrary paths for log files. An attacker could exploit this by creating a PHP file and causing LAM to log some PHP code to this file. When the file is then accessed via the web, the code would be executed. The issue is mitigated by the following: an attacker needs to know LAM's master configuration password to change the main settings, and the web server needs write access to a directory that is accessible via the web. LAM itself does not provide any such directories.
Recommendations As a temporary workaround, consider limiting access to LAM configuration pages to authorized users. Update to version 8.7 or later to resolve the issue.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-23333
GHSA-FM9W-7M7V-WXQV

Affected Products

Debian
Ldap Account Manager