<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – LDAP Injection (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ldap.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ldap-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – LDAP Injection (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44930 – An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44930</guid>
    <pubDate>Fri, 22 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44930</strong></p>
  <p>An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41919 – Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41919</guid>
    <pubDate>Tue, 19 May 2026 10:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41919</strong></p>
  <p>Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44671 – ZITADEL is an open source identity management platform. From 2.71.11 to before 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44671</guid>
    <pubDate>Thu, 14 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44671</strong></p>
  <p>ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search filters. This allows unauthenticated attackers to perform LDAP Filter Injection during the login process. While this vul…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27851 – When safe filter is used with variable expansion, all following pipelines on the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27851</guid>
    <pubDate>Tue, 12 May 2026 14:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27851</strong></p>
  <p>When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-235</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40459 – PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40459</guid>
    <pubDate>Fri, 17 Apr 2026 14:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40459</strong></p>
  <p>PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations.  This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40193 – maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40193</guid>
    <pubDate>Thu, 16 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40193</strong></p>
  <p>maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's ldap.EscapeFilter() function being available in the same import. This affects th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39962 – MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39962</guid>
    <pubDate>Thu, 09 Apr 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39962</strong></p>
  <p>MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable instead of REMOTE_USER (such as in certain proxy setups). An attacker able to control…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33289 – SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33289</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33289</strong></p>
  <p>SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied input before embedding it into the LDAP search filter. By injecting LDAP control characters, an unauthenticated attacker can…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31828 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31828</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31828</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpolated directly into LDAP Distinguished Names (DN) and group search filters without escaping special characters. This allows an attacker with valid LDA…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1498 – An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1498</guid>
    <pubDate>Fri, 30 Jan 2026 13:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1498</strong></p>
  <p>An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid pa…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12764 – pgAdmin &lt;= 9.9  is affected by an LDAP injection vulnerability in the LDAP authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12764</guid>
    <pubDate>Thu, 13 Nov 2025 13:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12764</strong></p>
  <p>pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48208 – Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48208</guid>
    <pubDate>Tue, 09 Sep 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48208</strong></p>
  <p>Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .             The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom commands. A successful attack would result in arbitrary script execution.  This issue affects Apache HertzBeat: through 1.7.2.  Users are recomme…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-54852 – When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54852</guid>
    <pubDate>Wed, 29 Jan 2025 22:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-54852</strong></p>
  <p>When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56841 – A vulnerability has been identified in Mendix LDAP (All versions &lt; V1.1.2). Affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56841</guid>
    <pubDate>Tue, 14 Jan 2025 11:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56841</strong></p>
  <p>A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37782 – An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37782</guid>
    <pubDate>Fri, 22 Nov 2024 18:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37782</strong></p>
  <p>An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2232 – A flaw was found in the Keycloak package. This flaw allows an attacker to utiliz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2232</guid>
    <pubDate>Thu, 14 Nov 2024 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2232</strong></p>
  <p>A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4727 – A flaw was found in dogtag-pki and pki-core. The token authentication scheme can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4727</guid>
    <pubDate>Tue, 11 Jun 2024 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4727</strong></p>
  <p>A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37393 – Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37393</guid>
    <pubDate>Mon, 10 Jun 2024 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37393</strong></p>
  <p>Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Admini…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33868 – An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33868</guid>
    <pubDate>Tue, 14 May 2024 16:17:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33868</strong></p>
  <p>An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41580 – Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41580</guid>
    <pubDate>Mon, 02 Oct 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41580</strong></p>
  <p>Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3447 – The Active Directory Integration / LDAP Integration plugin for WordPress is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3447</guid>
    <pubDate>Thu, 29 Jun 2023 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3447</strong></p>
  <p>The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to extract potentially sensitive information from the LDAP directory.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28853 – Mastodon is a free, open-source social network server based on ActivityPub Masto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28853</guid>
    <pubDate>Tue, 04 Apr 2023 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28853</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, an…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-25613 – An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25613</guid>
    <pubDate>Mon, 20 Feb 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-25613</strong></p>
  <p>An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23749 – The 'LDAP Integration with Active Directory and OpenLDAP - NTLM &amp; Kerberos Login...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23749</guid>
    <pubDate>Tue, 17 Jan 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23749</strong></p>
  <p>The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22360 – IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22360</guid>
    <pubDate>Tue, 19 Jul 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22360</strong></p>
  <p>IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39031 – IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39031</guid>
    <pubDate>Tue, 25 Jan 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39031</strong></p>
  <p>IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41232 – Thunderdome is an open source agile planning poker tool in the theme of Battling...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41232</guid>
    <pubDate>Tue, 02 Nov 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41232</strong></p>
  <p>Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been patched in version 1.16.3. If users are unable to update they should disable the LDAP feature if in use.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37933 – An LDAP injection vulnerability in /account/login in Huntflow Enterprise before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37933</guid>
    <pubDate>Thu, 14 Oct 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37933</strong></p>
  <p>An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logic of an LDAP query and bypass authentication. The vulnerability is due to insufficient server-side validation of the email parameter before using it to construct LDAP queries. An attacker could bypass authentication exploiting this vulnerability by s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-23148 – The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-23148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-23148</guid>
    <pubDate>Mon, 09 Aug 2021 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-23148</strong></p>
  <p>The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-23148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20574 – IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20574</guid>
    <pubDate>Mon, 28 Jun 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20574</strong></p>
  <p>IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29156 – ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29156</guid>
    <pubDate>Thu, 25 Mar 2021 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29156</strong></p>
  <p>ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35775 – CITSmart before 9.1.2.23 allows LDAP Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35775</guid>
    <pubDate>Mon, 15 Feb 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35775</strong></p>
  <p>CITSmart before 9.1.2.23 allows LDAP Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-23335 – All versions of package is-user-valid are vulnerable to LDAP Injection which can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23335</guid>
    <pubDate>Thu, 11 Feb 2021 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-23335</strong></p>
  <p>All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16212 – A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16212</guid>
    <pubDate>Fri, 25 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16212</strong></p>
  <p>A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16374 – Pega Platform 8.2.1 allows LDAP injection because a username can contain a * cha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16374</guid>
    <pubDate>Thu, 13 Aug 2020 13:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16374</strong></p>
  <p>Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5246 – Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5246</guid>
    <pubDate>Tue, 14 Jul 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5246</strong></p>
  <p>Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only impacts instances with LDAP configuration and where users can craft their own names. This has been patched in version 4.9.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11277 – Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11277</guid>
    <pubDate>Mon, 23 Sep 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11277</strong></p>
  <p>Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-12689 – phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12689</guid>
    <pubDate>Fri, 22 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-12689</strong></p>
  <p>phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4069 – html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to cond...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4069</guid>
    <pubDate>Thu, 01 Feb 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4069</strong></p>
  <p>html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7294 – ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7294</guid>
    <pubDate>Wed, 06 Sep 2017 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7294</strong></p>
  <p>ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8790 – An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8790</guid>
    <pubDate>Fri, 05 May 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8790</strong></p>
  <p>An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7472 – IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7472</guid>
    <pubDate>Mon, 15 Feb 2016 02:59:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7472</strong></p>
  <p>IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-6538 – The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6538</guid>
    <pubDate>Sun, 27 Dec 2015 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-6538</strong></p>
  <p>The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5649 – Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5649</guid>
    <pubDate>Thu, 08 Oct 2015 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5649</strong></p>
  <p>Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1169 – Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1169</guid>
    <pubDate>Tue, 10 Feb 2015 20:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1169</strong></p>
  <p>Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-5114 – WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5114</guid>
    <pubDate>Tue, 29 Jul 2014 14:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-5114</strong></p>
  <p>WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2051 – ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2051</guid>
    <pubDate>Thu, 05 Jun 2014 15:44:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2051</strong></p>
  <p>ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2051">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
