LDAP Injection Vulnerability in LibrIT PaSSHport

LDAP Injection Vulnerability in LibrIT PaSSHport

CVE-2021-3027 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.

Learn more about our Api Penetration Testing.