First published: Thu Jun 29 2023(Updated: )
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange Active Directory Integration / LDAP Integration | <4.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3447 is a vulnerability in the Active Directory Integration / LDAP Integration plugin for WordPress that allows for LDAP Injection due to insufficient escaping on the supplied username value.
CVE-2023-3447 has a severity rating of 7.5 (High).
CVE-2023-3447 affects versions up to and including 4.1.5 of the Active Directory Integration / LDAP Integration plugin for WordPress.
Unauthenticated attackers can exploit CVE-2023-3447 by using LDAP Injection to potentially extract sensitive information.
Yes, you can find more information about CVE-2023-3447 at the following references: [Reference 1](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2928150%40ldap-login-for-intranet-sites&new=2928150%40ldap-login-for-intranet-sites&sfp_email=&sfph_mail=) and [Reference 2](https://www.wordfence.com/threat-intel/vulnerabilities/id/cd7553e8-e43d-4740-b2ee-e3d8dc351e53?source=cve).