CVE-2024-54852 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper s…
Critical CVSS: 9.8

CVE-2024-54852

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
Vendor
Sismics
Product
Teedy
CWE
CWE-90
Yayın Tarihi
2025-01-29 22:15:29
Güncelleme
2025-05-24 01:14:43
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar