📦

ldap_integration_with_active_directory_and_openldap

Vendor: miniorange

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 0.56% Exploit Prob.
Latest CVE CVE-2023-23749 Jan 17

Security Vulnerability Index

Page 1 / 1
7.5 CVSS

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

EPSS: 0.56%