← Back

Ldap Tool Box Self Service Password

ldap_tool_box_self_service_password

Vendor: Ltb Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ltb Project
1Ldap Tool Box Self Service Password
Nov 21, 2024
Jun 14, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data...Show more
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.Show less