The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Joomla

Published: 2023-01-17T19:38:22.103Z

Updated:

Reserved: 2023-01-17T19:02:50.302Z


Link: CVE-2023-23749

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-01-17T20:15:11.983

Modified: 2023-01-27T18:18:38.047


Link: CVE-2023-23749

JSON object: View

cve-icon Redhat Information

No data.

CWE