medium.com
https://medium.com/%40cybertrinchera/cve-2023-4506-cve-2023-4505-ldap-passback-on-miniorange-plugins-ca7328c84313 CVE-2023-4505
LOW
Staff / Employee Business Directory for Active Directory <= 1.2.3 - Authenticated (Admin+) LDAP Passback
Record summary
CVE-2023-4505 has a selected CVSS score of 2.2 (low).
Description
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Staff/Employee Business Directory for Active DirectoryBrowse cyberlord92 / Staff/Employee Business Directory for Active DirectoryDefault status: unaffected | CVE List | Through 1.2.3 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4505 plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2973020 wordpress.org
https://wordpress.org/plugins/ldap-ad-staff-employee-directory-search wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/1ea40b96-4693-4f98-8e6e-2ed8186cedd8?source=cve