Active Directory Integration / LDAP Integration <= 4.1.9 - Unauthenticated Information Disclosure

2023-09-25 00:00
Pedro José Navas Pérez

Strategic Overview

Status
Patched in 4.1.10
Affected Version<= 4.1.9
CVSS5.3Medium
CVECVE-2023-5003
View all Active Directory Integration / LDAP Integration vulnerabilities

Vulnerability Overview

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.1.9 via log files that are left over and not deleted. This makes it possible for unauthenticated attackers to extract potentially sensitive data including errors and information contained in the plugin's log files.

Technical Analysis

REMEDIATION: Update to version 4.1.10, or a newer patched version --- IDENTIFIER: CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory) The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C