PT-2024-39431 · Unknown+2 · Phpldapadmin+2

·

CVE-2024-9102

·

Published

2024-12-19

·

Updated

2025-11-17

CVSS v4.0

5.0

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions phpLDAPadmin versions 1.2.0 through 1.2.6.7
Description The issue allows users to export elements from the LDAP directory into a Comma-Separated Value (CSV) file, but it does not neutralize special elements that could be interpreted as a command when the file is opened by a spreadsheet product. This could lead to CSV Formula Injection.
Recommendations For phpLDAPadmin versions 1.2.0 through 1.2.6.7, consider disabling the export functionality to CSV files until a patch is available to neutralize special elements. Restrict access to the export feature to minimize the risk of exploitation. Avoid opening CSV files exported from the LDAP directory in spreadsheet products that could interpret special elements as commands.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9102

Affected Products

Debian
Red Os
Phpldapadmin