CVE-2017-14596 โ€” LDAP Injection in Joomla !

CWE-90 โ€” LDAP Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
2.6%
top 14.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 20
Latest updateMay 17

Description

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

โ–ถNVDjoomla/joomla_!119 versions+118

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-c745-x889-v4rc: In Joomla! before 3โ†—2022-05-17
โ–ถ
CVEList
CVE-2017-14596: In Joomla! before 3โ†—2017-09-20
โ–ถ
CVE-2017-14596 โ€” LDAP Injection in Joomla ! | cvebase