CVE-2020-35775
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
15/02/2021
Last modified:
19/04/2021
Description
CITSmart before 9.1.2.23 allows LDAP Injection.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:citsmart:citsmart:*:*:*:*:*:*:*:* | 9.1.2.23 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/162181/CITSmart-ITSM-9.1.2.22-LDAP-Injection.html
- https://citsmart.com.br/solucoes/itsm-2/
- https://docs.citsmart.com/pt-br/citsmart-platform-9/get-started/about-citsmart/release-notes.html
- https://github.com/nardnet/citsmart/blob/master/WEB-INF/src/br/com/centralit/citcorpore/integracao/ad/LDAPUtils.java
- https://rdstation-static.s3.amazonaws.com/cms/files/86153/1597862259Ebook-Whatsnew-CITSmart.pdf



