The Ltb Project maintains self-service password management and LDAP administration tooling, a narrowly scoped portfolio of identity and directory utilities deployed primarily in organizations managing LDAP-based authentication infrastructure. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ltb Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12421CRITICAL LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind ret | Jun 14, 2018 | 9.8 | 29 | NO | NO |
CVE-2023-49032CRITICAL An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code fun | Dec 21, 2023 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ltb Project.
Media articles that mention a CVE ID that affects a product developed by Ltb Project — matched by CVE ID, not by vendor name.