LDAP injection in RoboHelp Server - CVE-2023-22272
Published: November 15, 2023 / Updated: November 16, 2023
RoboHelp Server
Adobe
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation when processing DLAP queries within the resolveDistinguishedName metho. A remote non-authenticated attacker can send a specially crafted LDAP query to the application and disclose sensitive information in the context of the application, including partial information about stored credentials.