Staff / Employee Business Directory for Active Directory <= 1.2.1 - Insufficient Escaping of Stored LDAP Values
Strategic Overview
- Status
- Patched in 1.2.3
- Affected Plugin
- Staff/Employee Business Directory for Active Directory
- Affected Version
<= 1.2.2- CVSS
- 5.4Medium
- Weakness type
- CWE-116 · Improper Encoding or Escaping of Output
- CVE
CVE-2023-4757
At a glance
CVE-2023-4757 is a medium-severity Improper Encoding or Escaping of Output vulnerability in the Staff/Employee Business Directory for Active Directory WordPress plugin, affecting versions <= 1.2.2. It carries a CVSS score of 5.4 (reachable over the network; low attack complexity). The issue is fixed in version 1.2.3; sites on affected versions should update now. Disclosed September 2023, reported by Pedro José Navas Pérez.
Vulnerability Overview
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to improper LDAP value escaping in versions up to, and including, 1.2.1. This is due to insufficient escaping on the supplied $user_field_data value. This makes it possible for authenticated attackers with access to edit their LDAP entries to inject malicious JavaScript that will access when a user accesses a page containing the data.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.
CWE-116: Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Remediation
Update to version 1.2.3, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Staff/Employee Business Directory for Active Directory 1.2.3 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Staff/Employee Business Directory for Active Directory
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C