LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.
References
Link | Resource |
---|---|
https://lists.ltb-project.org/pipermail/ltb-announce/2018-June/000023.html | Mailing List Patch Vendor Advisory |
https://github.com/ltb-project/self-service-password/issues/211 | Third Party Advisory |
https://github.com/ltb-project/self-service-password/issues/209 | Third Party Advisory |
Configurations
Information
Published : 2018-06-14 12:29
Updated : 2018-08-10 06:49
NVD link : CVE-2018-12421
Mitre link : CVE-2018-12421
JSON object : View
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Products Affected
ltb-project
- ldap_tool_box_self_service_password