Логотип exploitDog
bind:CVE-2024-54852
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-54852

Количество 2

Количество 2

nvd логотип

CVE-2024-54852

около 1 года назад

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-pm9m-75p4-7h69

около 1 года назад

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-54852

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-pm9m-75p4-7h69

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.

CVSS3: 9.8
1%
Низкий
около 1 года назад

Уязвимостей на страницу