Description:

Improper neutralization of special elements used in an LDAP query ('LDAP 
Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory 
authority connectors of Apache ManifoldCF allows an attacker to manipulate the 
LDAP search queries (DoS, additional queries, filter manipulation) during user 
lookup, if the username or the domain string are passed to the UserACLs servlet 
without validation.

This issue affects Apache ManifoldCF version 2.23 and prior versions.

Credit:

4ra1n of Chaitin Tech (finder)

References:

https://manifoldcf.apache.org/
https://cve.org/CVERecord?id=CVE-2022-45910

Reply via email to