CVE-2023-23749

HIGH

LDAP Integration with Active Directory and OpenLDAP - LDAP Injection via Username Parameter

Title source: llm
STIX 2.1

Description

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74
Status published
Products (1)
miniorange/ldap_integration_with_active_directory_and_openldap 5.0.2
Published Jan 17, 2023
Tracked Since Feb 18, 2026