ZeroHour

CVE-2021-3825

PoC
CVSS 3.1
9.6 critical
EPSS
2%p75
Published
()
Modified
Description

On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.

Vendors
pardus
Products
liderahenk
Weakness
CWE-306
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.