CVE Database
/

CVE-2023-23749

Back to search

CVE-2023-23749

Published: Jan 17, 2023

Modified: Apr 4, 2025

PUBLISHED

Description

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

VendorProductVersions

miniorange

LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login

affected
5.0.2
unaffected
6.0.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now