Improper neutralization of special elements used in an...
Moderate severity
Unreviewed
Published
Dec 7, 2022
to the GitHub Advisory Database
•
Updated Jul 1, 2023
Description
Published by the National Vulnerability Database
Dec 7, 2022
Published to the GitHub Advisory Database
Dec 7, 2022
Last updated
Jul 1, 2023
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions.
References