ZeroHour

CVE-2021-3027

CVSS 3.1
6.5 medium
EPSS
1%p66
Published
()
Modified
Description

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.

Vendors
librit
Products
passhport
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.