Vulnerability Description
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sismics | Teedy | >= 1.9, <= 1.12 |
Related Weaknesses (CWE)
References
- https://github.com/Tanguy-Boisset/CVE/blob/master/CVE-2024-54852/README.mdExploitThird Party Advisory
- https://github.com/Tanguy-Boisset/CVE/blob/master/CVE-2024-54852/README.mdExploitThird Party Advisory
FAQ
What is CVE-2024-54852?
CVE-2024-54852 is a vulnerability with a CVSS score of 9.8 (CRITICAL). When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenti...
How severe is CVE-2024-54852?
CVE-2024-54852 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-54852?
Check the references section above for vendor advisories and patch information. Affected products include: Sismics Teedy.