CVE-2022-2987
Summary
| CVE | CVE-2022-2987 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-26 13:15:00 UTC |
| Updated | 2023-07-20 18:24:00 UTC |
| Description | The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated users, therefore bypassing the current authentication |
Risk And Classification
Problem Types: CWE-352 | CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ldap Wp Login Active Directory Integration Project | Ldap Wp Login / Active Directory Integration | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ldap WP Login / Active Directory Integration < 3.0.2 - Unauthenticated Settings Update to Auth Bypass WordPress Security Vulnerability | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Lana Codes
There are currently no legacy QID mappings associated with this CVE.