Vulnerability Description
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miniorange | Active Directory Integration \/ Ldap Integration | < 4.1.10 |
References
- https://wpscan.com/vulnerability/91f4e500-71f3-4ef6-9cc7-24a7c12a5748ExploitThird Party Advisory
- https://wpscan.com/vulnerability/91f4e500-71f3-4ef6-9cc7-24a7c12a5748ExploitThird Party Advisory
FAQ
What is CVE-2023-5003?
CVE-2023-5003 is a vulnerability with a CVSS score of 7.5 (HIGH). The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log ...
How severe is CVE-2023-5003?
CVE-2023-5003 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5003?
Check the references section above for vendor advisories and patch information. Affected products include: Miniorange Active Directory Integration \/ Ldap Integration.