Описание
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-37782
- https://gist.githubusercontent.com/Draoken/ab5465fc339df7a1e42281540b61f887/raw/fb28d4148e311e8cde9778dee4f8b2e64e27ea92/CVE-2024-37782.txt
- https://medium.com/%40jkoreamo/centrestack-vulnerability-disclosure-d28dc8f21a56
- https://www.centrestack.com/p/gce_latest_release.html
Связанные уязвимости
CVSS3: 9.8
nvd
около 1 года назад
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.