CVE-2023-23749 - CVE House
Back to Database
Status published Unknown CVE-2023-23749

Extension - miniorange - LDAP Integration - LDAP Injection (username)

Vulnerability Description

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-23749

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login
Vulnerable Versions:
5.0.2, 6.0.0

Timeline

Official Publish: January 17th, 2023
Last Modified: April 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.