VDB
CVE-2023-5003
CVE-2023-5003
PUBLISHED
CVSS 7.5 HIGH
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
EPSS 25.85% · 97.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
25.85%
97.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| miniorange | active_directory_integration_\/_ldap_integration | 0, 0 |
| Unknown | Active Directory Integration / LDAP Integration | 0, 0 |
Timeline
- Jan 20, 1970 Nuclei Template
- Jan 20, 1970 Fix Commit
- Oct 16, 2023 CVE Published
- Oct 17, 2023 EPSS Score
- Oct 17, 2023 PoC Published
- Nov 17, 2023 EPSS Score
- Jan 19, 2024 EPSS Score
- Feb 19, 2024 EPSS Score
- Mar 21, 2024 EPSS Score
- Apr 4, 2024 CVE Updated
- Apr 21, 2024 EPSS Score
- Jun 23, 2024 EPSS Score