CVE-2023-23749 describes an LDAP Injection vulnerability in the miniorange 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension. This flaw, rated 7.5 HIGH, allows an unauthenticated attacker to extract arbitrary data from the LDAP database by manipulating the 'username' POST parameter. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no evidence of active exploitation, the vulnerability's high severity and ease of exploitation warrant attention. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.2CPE matchmatch criteria | cpe:2.3:a:miniorange:ldap_integration_with_active_directory_and_openldap:5.0.2:*:*:*:*:joomla\!:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.