PT-2024-19815 · Unknown+1 · Ldap Account Manager+1
Maik-S
·
Published
2024-03-18
·
Updated
2025-12-23
·
CVE-2024-23333
CVSS v3.1
7.9
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
LDAP Account Manager (LAM) versions prior to 8.7
Description
LDAP Account Manager (LAM) is a web frontend for managing entries stored in an LDAP directory. LAM's log configuration allows specifying arbitrary paths for log files. An attacker could exploit this by creating a PHP file and causing LAM to log some PHP code to this file. When the file is then accessed via the web, the code would be executed. The issue is mitigated by the following: an attacker needs to know LAM's master configuration password to change the main settings, and the web server needs write access to a directory that is accessible via the web. LAM itself does not provide any such directories.
Recommendations
As a temporary workaround, consider limiting access to LAM configuration pages to authorized users.
Update to version 8.7 or later to resolve the issue.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Ldap Account Manager