漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WeKan < 8.19 LDAP Authentication Filter Injection
Vulnerability Description
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
CVSS Information
N/A
Vulnerability Type
LDAP查询中使用的特殊元素转义处理不恰当(LDAP注入)
Vulnerability Title
WeKan 注入漏洞
Vulnerability Description
WeKan是WeKan开源的一个看板应用程序。 WeKan 8.19之前版本存在注入漏洞,该漏洞源于LDAP身份验证中用户提供的用户名输入未经充分转义即并入LDAP搜索过滤器和DN相关值,可能导致LDAP过滤器注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A