The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/91f4e500-71f3-4ef6-9cc7-24a7c12a5748 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2023-10-16T19:39:08.657Z
Updated: 2023-10-16T19:39:08.657Z
Reserved: 2023-09-15T19:38:39.194Z
Link: CVE-2023-5003
JSON object: View
NVD Information
Status : Modified
Published: 2023-10-16T20:15:17.490
Modified: 2023-11-07T04:23:17.990
Link: CVE-2023-5003
JSON object: View
Redhat Information
No data.
CWE
No CWE.