CVE-2023-5003
16.10.2023, 20:15
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.Enginsight
Vendor | Product | Version |
---|---|---|
miniorange | active_directory_integration_\/_ldap_integration | 𝑥 < 4.1.10 |
𝑥
= Vulnerable software versions