Loading HuntDB...

GHSA-mjch-v7j4-5xmp

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

Related CVEs

Key Information

GHSA ID
GHSA-mjch-v7j4-5xmp
Published
September 27, 2023 3:30 PM
Last Modified
April 4, 2024 7:55 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.