216.73.216.233

CVE-2024-54852

· Published 29/01/2025 22:15 · Modified 10/02/2025 22:15

Labels: CVE-2024-54852 2025-01-29CVE-2024-54852CWE-90[email protected]

Essential information

Published
29/01/2025 22:15
Modified
10/02/2025 22:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References