CVE-2023-41580
02.10.2023, 13:15
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
Vendor | Product | Version |
---|---|---|
phpipam | phpipam | 𝑥 < 1.5.2 |
𝑥
= Vulnerable software versions