LDAP injection in RoboHelp Server - CVE-2023-22272

 

LDAP injection in RoboHelp Server - CVE-2023-22272

Published: November 15, 2023 / Updated: November 16, 2023


Vulnerability identifier: #VU83153
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22272
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation when processing DLAP queries within the resolveDistinguishedName metho. A remote non-authenticated attacker can send a specially crafted LDAP query to the application and disclose sensitive information in the context of the application, including partial information about stored credentials.


Affected software

RoboHelp Server

How to mitigate CVE-2023-22272

Install updates from vendor's website.

RoboHelp Server - update to 11.5

External References

Related Security Bulletins