Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32793
HistoryNov 03, 2021 - 4:37 a.m.

LDAP Injection

2021-11-0304:37:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29
ldap injection
remote attackers
directory service
sensitive information
vulnerable software

EPSS

0.003

Percentile

70.1%

github.com/stevenweathers/thunderdome-planning-poker is vulnerable to LDAP injection. Lack of an escape filter allows remote attackers to inject specially crafted values through UserName parameter resulting in LDAP injection vulnerability. Successful attackers are able to read, modify or delete sensitive information from the directory service.

EPSS

0.003

Percentile

70.1%

Related for VERACODE:32793