CVE-2018-12689: Critical severity phpldapadmin vulnerability
Published Jun 22, 2018
·Updated
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted serverid parameter in a cmd.php?cmd=loginform request, or a crafted username and password in the login panel.
Affected Software
1 affected component
Phpldapadmin Project Phpldapadmin=1.2.2
Event History
Jun 22, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12689?
CVE-2018-12689 has a severity rating that suggests it is a moderate vulnerability due to the potential for LDAP injection attacks.
2
How do I fix CVE-2018-12689?
To fix CVE-2018-12689, update phpLDAPadmin to version 1.2.3 or later.
3
What does CVE-2018-12689 allow attackers to do?
CVE-2018-12689 allows attackers to perform LDAP injection through crafted parameters that can manipulate LDAP queries.
4
Is CVE-2018-12689 exploitable?
Yes, CVE-2018-12689 is exploitable if the affected version of phpLDAPadmin is exposed to untrusted input.
5
Which versions of phpLDAPadmin are affected by CVE-2018-12689?
CVE-2018-12689 affects phpLDAPadmin version 1.2.2.