medium.com
https://medium.com/%40cybertrinchera/cve-2023-4506-cve-2023-4505-ldap-passback-on-miniorange-plugins-ca7328c84313 CVE-2023-4506
LOW
Active Directory Integration / LDAP Integration <= 4.1.10 - LDAP Passback
Record summary
CVE-2023-4506 has a selected CVSS score of 2.2 (low).
Description
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Active Directory Integration / LDAP IntegrationBrowse cyberlord92 / Active Directory Integration / LDAP IntegrationDefault status: unaffected | CVE List | Through 4.1.10 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4506 plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2973005/ldap-login-for-intranet-sites wordpress.org
https://wordpress.org/plugins/ldap-login-for-intranet-sites wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/0585969d-dd08-4058-9d72-138a55a2cdf1?source=cve