Lucene search

K
wpvulndbWpvulndbWPVDB-ID:4894B09E-4D30-4DE3-8B7E-037A4C3CF207
HistoryMay 12, 2023 - 12:00 a.m.

Active Directory Integration < 4.1.5 - SQL Injection via CSRF

2023-05-1200:00:00
wpscan.com
2
active directory
integration
sql injection
csrf
software
plugin
nonces
parameters
cross-site request forgery
vulnerabilities
orderby
order

0.002 Low

EPSS

Percentile

57.0%

The plugin does not properly verify nonces and sufficiently escape user-supplied parameters, leading to Cross-Site Request Forgery and time-based SQL Injection vulnerabilities via the orderby and order parameters.

CPENameOperatorVersion
ldap-login-for-intranet-siteslt4.1.5

0.002 Low

EPSS

Percentile

57.0%

Related for WPVDB-ID:4894B09E-4D30-4DE3-8B7E-037A4C3CF207