VDB

CVE-2023-5003

CVE-2023-5003 PUBLISHED CVSS 7.5 HIGH

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

EPSS 25.85% · 97.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
25.85%
97.8th percentile

Affected Products

VendorProductVersions
miniorangeactive_directory_integration_\/_ldap_integration0, 0
UnknownActive Directory Integration / LDAP Integration0, 0

Timeline

  • Jan 20, 1970 Nuclei Template
  • Jan 20, 1970 Fix Commit
  • Oct 16, 2023 CVE Published
  • Oct 17, 2023 EPSS Score
  • Oct 17, 2023 PoC Published
  • Nov 17, 2023 EPSS Score
  • Jan 19, 2024 EPSS Score
  • Feb 19, 2024 EPSS Score
  • Mar 21, 2024 EPSS Score
  • Apr 4, 2024 CVE Updated
  • Apr 21, 2024 EPSS Score
  • Jun 23, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›