First published: Wed Apr 03 2024(Updated: )
In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated attacker to discover information about registered users via an LDAP injection attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VeridiumID | <3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44038 has a medium severity rating due to the risk of information disclosure from an LDAP injection attack.
To fix CVE-2023-44038, upgrade VeridiumID to version 3.5.0 or later to patch the vulnerability.
CVE-2023-44038 allows unauthenticated attackers to gather information about registered users, potentially compromising their security.
Yes, CVE-2023-44038 specifically affects versions of VeridiumID prior to 3.5.0.
Yes, CVE-2023-44038 can be exploited remotely by an unauthenticated attacker.