CVE-2023-4757

Staff / Employee Business Directory for Active Directory <= 1.2.1 - Insufficient Escaping of Stored LDAP Values

2023-09-08 00:00
Pedro José Navas Pérez

Strategic Overview

Status
Patched in 1.2.3
Affected Version
<= 1.2.2
CVSS
5.4Medium
Weakness type
CWE-116 · Improper Encoding or Escaping of Output
CVE
CVE-2023-4757
View all Staff/Employee Business Directory for Active Directory vulnerabilities

At a glance

CVE-2023-4757 is a medium-severity Improper Encoding or Escaping of Output vulnerability in the Staff/Employee Business Directory for Active Directory WordPress plugin, affecting versions <= 1.2.2. It carries a CVSS score of 5.4 (reachable over the network; low attack complexity). The issue is fixed in version 1.2.3; sites on affected versions should update now. Disclosed September 2023, reported by Pedro José Navas Pérez.

Vulnerability Overview

The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to improper LDAP value escaping in versions up to, and including, 1.2.1. This is due to insufficient escaping on the supplied $user_field_data value. This makes it possible for authenticated attackers with access to edit their LDAP entries to inject malicious JavaScript that will access when a user accesses a page containing the data.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.

CWE-116: Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Remediation

Update to version 1.2.3, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Staff/Employee Business Directory for Active Directory 1.2.3 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Other vulnerabilities in Staff/Employee Business Directory for Active Directory

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C