#VU101881 Path traversal in LDAP Account Manager - CVE-2024-52792
Published: December 20, 2024
LDAP Account Manager
LDAP Account Manager
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences in in mainmanage.php and confmain.php scripts. A remote user can modify configuration variables, including the log file path and execute arbitrary PHP code on the system.