HIGH
Extension - miniorange - LDAP Integration - LDAP Injection (username)
Published Jan 17, 2023
7.5
HIGHCVSS 3.1
EPSS 0.56%
Description
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
Affected products
- Vendor Miniorange Product LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login Defaultaffected
Affected
- 5.0.2
Unaffected
- 6.0.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Miniorange | LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login | affected | Affected
Unaffected
|
- 5.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-27835 Advisory
- https://extensions.joomla.org/vulnerable-extensions/resolved/ldap-integration-with-active-directory-and-openldap-ntlm-kerberos-login-5-0-2-other/ vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-27835 | Advisory | |
| https://extensions.joomla.org/vulnerable-extensions/resolved/ldap-integration-with-active-directory-and-openldap-ntlm-kerberos-login-5-0-2-other/ | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Joomla
Published Jan 17, 2023
Updated Apr 4, 2025
Reserved Jan 17, 2023
Link CVE-2023-23749
CISA Vulnrichment
Updated Apr 2, 2025
Red Hat
No data
GitHub
No data