CVE-2023-0812: Active Directory Integration / LDAP Integration < 4.1.1 - Unauthenticated Data Disclosure
Published May 15, 2023
·Updated
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
Affected Software
1 affected component
miniOrange Active Directory Integration \/ Ldap Integration Wordpress<4.1.1
Event History
May 15, 2023
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-0812.
2
What is the title of this vulnerability?
The title of this vulnerability is "The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure."
3
What is the severity of CVE-2023-0812?
The severity of CVE-2023-0812 is high.
4
What is the affected software for CVE-2023-0812?
The affected software for CVE-2023-0812 is the Miniorange Active Directory Integration / Ldap Integration WordPress plugin before version 4.1.1.
5
What is the CWE (Common Weakness Enumeration) for CVE-2023-0812?
The CWE for CVE-2023-0812 is CWE-200.