First published: Tue Jan 17 2023(Updated: )
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange Active Directory Integration / LDAP Integration | =5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-23749.
The title of the vulnerability is 'The LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login extension is vulnerable to LDAP Injection'.
The severity of CVE-2023-23749 is high with a CVSS score of 7.5.
CVE-2023-23749 affects the LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login extension by allowing LDAP Injection due to improper sanitization of the 'username' POST parameter.
Yes, a fix for CVE-2023-23749 is available. It is recommended to update to the latest version of the LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login extension.