The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for unauthenticated attackers to extract potentially sensitive information from the LDAP directory.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-06-29T04:28:35.916Z
Updated: 2023-06-29T04:28:35.916Z
Reserved: 2023-06-28T16:19:19.045Z
Link: CVE-2023-3447
JSON object: View
NVD Information
Status : Modified
Published: 2023-06-29T05:15:14.177
Modified: 2023-11-07T04:18:44.433
Link: CVE-2023-3447
JSON object: View
Redhat Information
No data.
CWE
No CWE.