CVE-2021-3027 Information

Description

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries escaping the provided search filter because user input gets no sanitization.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Reference

https://jorgectf.gitlab.io/disclosure/cve-2021-3027/ https://github.com/LibrIT/passhport/pull/562 https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.5

Share on: