LDAP injection in RoboHelp Server - CVE-2023-22272

 

LDAP injection in RoboHelp Server - CVE-2023-22272

Published: November 15, 2023 / Updated: November 16, 2023


Vulnerability identifier: #VU83153
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-22272
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
RoboHelp Server
Software vendor:
Adobe

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation when processing DLAP queries within the resolveDistinguishedName metho. A remote non-authenticated attacker can send a specially crafted LDAP query to the application and disclose sensitive information in the context of the application, including partial information about stored credentials.


Remediation

Install updates from vendor's website.

External links