CVE-2021-3027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
26/03/2021
Last modified:
03/05/2022

Description

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:librit:passhport:*:*:*:*:*:*:*:* 2.5 (including)