First published: Tue Jan 16 2024(Updated: )
The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Miniorange Staff / Employee Business Directory For Active Directory | <1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4757 is considered a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2023-4757, update the Staff / Employee Business Directory for Active Directory plugin to version 1.2.3 or later.
CVE-2023-4757 allows attackers to inject malicious JavaScript into web pages, potentially compromising user data and security.
Anyone using the Staff / Employee Business Directory for Active Directory plugin versions prior to 1.2.3 is vulnerable to CVE-2023-4757.
CVE-2023-4757 is classified as a cross-site scripting (XSS) vulnerability.