In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.
Link | Tags |
---|---|
https://developer.joomla.org/security-centre/711-20170902-core-ldap-information-disclosure | vendor advisory |
https://blog.ripstech.com/2017/joomla-takeover-in-20-seconds-with-ldap-injection-cve-2017-14596/ | exploit third party advisory technical description |
http://www.securitytracker.com/id/1039407 | vdb entry third party advisory |
http://www.securityfocus.com/bid/100898 | vdb entry third party advisory |