Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS...
Moderate severity
Unreviewed
Published
Oct 26, 2023
to the GitHub Advisory Database
•
Updated Nov 25, 2023
Description
Published by the National Vulnerability Database
Oct 26, 2023
Published to the GitHub Advisory Database
Oct 26, 2023
Last updated
Nov 25, 2023
Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a teacher can gain administrator access via an NTLM hash.
References