<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – LDAP Injection</title>
  <link>https://cvedaily.com/pages/tags/ldap.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ldap.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – LDAP Injection</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-44930 – An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44930</guid>
    <pubDate>Fri, 22 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44930</strong></p>
  <p>An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44063 – An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44063</guid>
    <pubDate>Thu, 21 May 2026 08:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44063</strong></p>
  <p>An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP entries via crafted filter input.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41919 – Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41919</guid>
    <pubDate>Tue, 19 May 2026 10:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41919</strong></p>
  <p>Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.  This issue affects Apache OFBiz: before 24.09.06.  Users are recommended to upgrade to version 24.09.06, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44671 – ZITADEL is an open source identity management platform. From 2.71.11 to before 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44671</guid>
    <pubDate>Thu, 14 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44671</strong></p>
  <p>ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search filters. This allows unauthenticated attackers to perform LDAP Filter Injection during the login process. While this vul…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27851 – When safe filter is used with variable expansion, all following pipelines on the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27851</guid>
    <pubDate>Tue, 12 May 2026 14:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27851</strong></p>
  <p>When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-235</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40459 – PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40459</guid>
    <pubDate>Fri, 17 Apr 2026 14:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40459</strong></p>
  <p>PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations.  This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40193 – maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40193</guid>
    <pubDate>Thu, 16 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40193</strong></p>
  <p>maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's ldap.EscapeFilter() function being available in the same import. This affects th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0636 – Improper neutralization of special elements used in an LDAP query ('LDAP injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0636</guid>
    <pubDate>Wed, 15 Apr 2026 10:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0636</strong></p>
  <p>Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).   This vulnerability is associated with program files LDAPStoreHelper.    This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39962 – MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39962</guid>
    <pubDate>Thu, 09 Apr 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39962</strong></p>
  <p>MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable instead of REMOTE_USER (such as in certain proxy setups). An attacker able to control…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33369 – Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33369</guid>
    <pubDate>Fri, 20 Mar 2026 14:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33369</strong></p>
  <p>Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated attacker can exploit this issue by sending a crafted SOAP request that manipulates the LDAP query, allowing retrieval of sen…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33289 – SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33289</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33289</strong></p>
  <p>SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied input before embedding it into the LDAP search filter. By injecting LDAP control characters, an unauthenticated attacker can…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31828 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31828</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31828</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpolated directly into LDAP Distinguished Names (DN) and group search filters without escaping special characters. This allows an attacker with valid LDA…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1498 – An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1498</guid>
    <pubDate>Fri, 30 Jan 2026 13:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1498</strong></p>
  <p>An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid pa…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21880 – Kanboard is project management software focused on Kanban methodology. Versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21880</guid>
    <pubDate>Thu, 08 Jan 2026 02:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21880</strong></p>
  <p>Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users, discover sensitive user attributes, and perform targeted attacks against specific…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12764 – pgAdmin &lt;= 9.9  is affected by an LDAP injection vulnerability in the LDAP authe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12764</guid>
    <pubDate>Thu, 13 Nov 2025 13:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12764</strong></p>
  <p>pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61911 – python-ldap is a lightweight directory access protocol (LDAP) client API for Pyt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61911</guid>
    <pubDate>Fri, 10 Oct 2025 22:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61911</strong></p>
  <p>python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to skip escaping of special characters when a crafted `list` or `dict` is supplied as the `assertion_value` parameter, and the non-default `escape_mode=1` is configured. The method `ldap.filter.escape_filter_chars…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-75</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48208 – Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48208</guid>
    <pubDate>Tue, 09 Sep 2025 10:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48208</strong></p>
  <p>Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .             The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom commands. A successful attack would result in arbitrary script execution.  This issue affects Apache HertzBeat: through 1.7.2.  Users are recomme…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-52575 – EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52575</guid>
    <pubDate>Mon, 21 Jul 2025 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-52575</strong></p>
  <p>EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries by injecting crafted input containing wildcard characters (e.g., *). This may allow the attacker to bypass authentication controls, enumerate valid us…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-27686 – Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27686</guid>
    <pubDate>Mon, 07 Apr 2025 14:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-27686</strong></p>
  <p>Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27631 – The TRMTracker web application is vulnerable to LDAP injection attack potentiall...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27631</guid>
    <pubDate>Tue, 25 Mar 2025 13:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27631</strong></p>
  <p>The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-54852 – When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54852</guid>
    <pubDate>Wed, 29 Jan 2025 22:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-54852</strong></p>
  <p>When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56841 – A vulnerability has been identified in Mendix LDAP (All versions &lt; V1.1.2). Affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56841</guid>
    <pubDate>Tue, 14 Jan 2025 11:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56841</strong></p>
  <p>A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37782 – An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37782</guid>
    <pubDate>Fri, 22 Nov 2024 18:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37782</strong></p>
  <p>An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2232 – A flaw was found in the Keycloak package. This flaw allows an attacker to utiliz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2232</guid>
    <pubDate>Thu, 14 Nov 2024 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2232</strong></p>
  <p>A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4727 – A flaw was found in dogtag-pki and pki-core. The token authentication scheme can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4727</guid>
    <pubDate>Tue, 11 Jun 2024 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4727</strong></p>
  <p>A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37393 – Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37393</guid>
    <pubDate>Mon, 10 Jun 2024 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37393</strong></p>
  <p>Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Admini…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-33868 – An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33868</guid>
    <pubDate>Tue, 14 May 2024 16:17:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-33868</strong></p>
  <p>An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44038 – In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44038</guid>
    <pubDate>Wed, 03 Apr 2024 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44038</strong></p>
  <p>In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated attacker to discover information about registered users via an LDAP injection attack.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-51446 – GLPI is a Free Asset and IT Management Software package. When authentication is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51446</guid>
    <pubDate>Thu, 01 Feb 2024 18:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-51446</strong></p>
  <p>GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6905 – A vulnerability, which was classified as problematic, has been found in Jahastec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6905</guid>
    <pubDate>Mon, 18 Dec 2023 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6905</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler. The manipulation leads to ldap injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-248267. NOTE: The vendor was contac…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41580 – Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41580</guid>
    <pubDate>Mon, 02 Oct 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41580</strong></p>
  <p>Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-33201 – Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33201</guid>
    <pubDate>Wed, 05 Jul 2023 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-33201</strong></p>
  <p>Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3447 – The Active Directory Integration / LDAP Integration plugin for WordPress is vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3447</guid>
    <pubDate>Thu, 29 Jun 2023 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3447</strong></p>
  <p>The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to extract potentially sensitive information from the LDAP directory.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45801 – Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability.
LDAP Injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45801</guid>
    <pubDate>Mon, 01 May 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45801</strong></p>
  <p>Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements through techniques similar to SQL Injection. LDAP injection attacks could result in the granting of permissions…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28853 – Mastodon is a free, open-source social network server based on ActivityPub Masto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28853</guid>
    <pubDate>Tue, 04 Apr 2023 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28853</strong></p>
  <p>Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Starting in version 2.5.0 and prior to versions 3.5.8, 4.0.4, and 4.1.2, the LDAP query made during login is insecure and the attacker can perform LDAP injection attack to leak arbitrary attributes from LDAP database. This issue is fixed in versions 3.5.8, 4.0.4, an…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-25613 – An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25613</guid>
    <pubDate>Mon, 20 Feb 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-25613</strong></p>
  <p>An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0476 – A LDAP injection vulnerability exists in Tenable.sc due to improper validation o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0476</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0476</strong></p>
  <p>A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23749 – The 'LDAP Integration with Active Directory and OpenLDAP - NTLM &amp; Kerberos Login...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23749</guid>
    <pubDate>Tue, 17 Jan 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23749</strong></p>
  <p>The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-10027 – A vulnerability, which was classified as problematic, has been found in hydrian ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-10027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-10027</guid>
    <pubDate>Sat, 07 Jan 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-10027</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to version 2.0b1 is able to address this issue. The patch is identified as a7f7a5a82d9202a5c40d606a5c519ba61b224eb8. It is recommended to upgrade the affected com…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-10027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45910 – Improper neutralization of special elements used in an LDAP query ('LDAP Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45910</guid>
    <pubDate>Wed, 07 Dec 2022 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45910</strong></p>
  <p>Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without vali…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22360 – IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22360</guid>
    <pubDate>Tue, 19 Jul 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22360</strong></p>
  <p>IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 220782.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39031 – IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39031</guid>
    <pubDate>Tue, 25 Jan 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39031</strong></p>
  <p>IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41232 – Thunderdome is an open source agile planning poker tool in the theme of Battling...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41232</guid>
    <pubDate>Tue, 02 Nov 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41232</strong></p>
  <p>Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been patched in version 1.16.3. If users are unable to update they should disable the LDAP feature if in use.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37933 – An LDAP injection vulnerability in /account/login in Huntflow Enterprise before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37933</guid>
    <pubDate>Thu, 14 Oct 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37933</strong></p>
  <p>An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logic of an LDAP query and bypass authentication. The vulnerability is due to insufficient server-side validation of the email parameter before using it to construct LDAP queries. An attacker could bypass authentication exploiting this vulnerability by s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-23148 – The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-23148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-23148</guid>
    <pubDate>Mon, 09 Aug 2021 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-23148</strong></p>
  <p>The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-23148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20574 – IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20574</guid>
    <pubDate>Mon, 28 Jun 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20574</strong></p>
  <p>IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-32651 – OneDev is a development operations platform. If the LDAP external authentication...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32651</guid>
    <pubDate>Tue, 01 Jun 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-32651</strong></p>
  <p>OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue wa…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3027 – app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3027</guid>
    <pubDate>Fri, 26 Mar 2021 03:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3027</strong></p>
  <p>app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29156 – ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29156</guid>
    <pubDate>Thu, 25 Mar 2021 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29156</strong></p>
  <p>ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-36144 – Redash 8.0.0 is affected by LDAP Injection. There is an information leak through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36144</guid>
    <pubDate>Thu, 18 Mar 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-36144</strong></p>
  <p>Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35775 – CITSmart before 9.1.2.23 allows LDAP Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35775</guid>
    <pubDate>Mon, 15 Feb 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35775</strong></p>
  <p>CITSmart before 9.1.2.23 allows LDAP Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-23335 – All versions of package is-user-valid are vulnerable to LDAP Injection which can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23335</guid>
    <pubDate>Thu, 11 Feb 2021 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-23335</strong></p>
  <p>All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16212 – A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16212</guid>
    <pubDate>Fri, 25 Sep 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16212</strong></p>
  <p>A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16374 – Pega Platform 8.2.1 allows LDAP injection because a username can contain a * cha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16374</guid>
    <pubDate>Thu, 13 Aug 2020 13:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16374</strong></p>
  <p>Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5246 – Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5246</guid>
    <pubDate>Tue, 14 Jul 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5246</strong></p>
  <p>Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only impacts instances with LDAP configuration and where users can craft their own names. This has been patched in version 4.9.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9495 – Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9495</guid>
    <pubDate>Fri, 19 Jun 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9495</strong></p>
  <p>Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11277 – Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11277</guid>
    <pubDate>Mon, 23 Sep 2019 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11277</strong></p>
  <p>Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-4297 – IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4297</guid>
    <pubDate>Mon, 01 Jul 2019 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-4297</strong></p>
  <p>IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-12689 – phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12689</guid>
    <pubDate>Fri, 22 Jun 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-12689</strong></p>
  <p>phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-8750 – Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8750</guid>
    <pubDate>Mon, 19 Feb 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-8750</strong></p>
  <p>Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4069 – html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to cond...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4069</guid>
    <pubDate>Thu, 01 Feb 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4069</strong></p>
  <p>html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7294 – ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7294</guid>
    <pubDate>Wed, 06 Sep 2017 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7294</strong></p>
  <p>ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8790 – An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8790</guid>
    <pubDate>Fri, 05 May 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8790</strong></p>
  <p>An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9870 – EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9870</guid>
    <pubDate>Mon, 23 Jan 2017 07:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9870</strong></p>
  <p>EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, and EMC Isilon OneFS 7.1.0.x is affected by an LDAP injection vulnerability that could potentially be exploited by a malicious user to compromise the system.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7472 – IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7472</guid>
    <pubDate>Mon, 15 Feb 2016 02:59:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7472</strong></p>
  <p>IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-7466 – Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7466</guid>
    <pubDate>Sun, 10 Jan 2016 03:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-7466</strong></p>
  <p>Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-6538 – The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6538</guid>
    <pubDate>Sun, 27 Dec 2015 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-6538</strong></p>
  <p>The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5649 – Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5649</guid>
    <pubDate>Thu, 08 Oct 2015 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5649</strong></p>
  <p>Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1169 – Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1169</guid>
    <pubDate>Tue, 10 Feb 2015 20:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1169</strong></p>
  <p>Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-5114 – WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5114</guid>
    <pubDate>Tue, 29 Jul 2014 14:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-5114</strong></p>
  <p>WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2051 – ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2051</guid>
    <pubDate>Thu, 05 Jun 2014 15:44:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2051</strong></p>
  <p>ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-6943 – Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6943</guid>
    <pubDate>Tue, 11 Mar 2014 13:00:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-6943</strong></p>
  <p>Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-4744 – Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4744</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-4744</strong></p>
  <p>Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail.  NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-2301 – PowerDNS before 2.9.18, when running with an LDAP backend, does not properly esc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2301</guid>
    <pubDate>Tue, 19 Jul 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-2301</strong></p>
  <p>PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2301">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
