CVE-2023-23749
Summary
| CVE | CVE-2023-23749 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-17 20:15:00 UTC |
| Updated | 2023-01-27 18:18:00 UTC |
| Description | The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Miniorange | Ldap Integration With Active Directory And Openldap | 5.0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login , 5.0.2, Other | MISC | extensions.joomla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.