Back

HIGH

Extension - miniorange - LDAP Integration - LDAP Injection (username)

Published Jan 17, 2023

Description

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Joomla
Published Jan 17, 2023
Updated Apr 4, 2025
Reserved Jan 17, 2023

CISA Vulnrichment

Updated Apr 2, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Joomla
Published Jan 17, 2023
Updated Apr 4, 2025

GitHub

No data