WeKan
cpe:2.3:a:wekan_project:wekan:*:*:*:*:*:*:*
- < 8.19
A vulnerability allowing LDAP filter injection has been identified in WeKan versions prior to 8.19. This issue arises in the LDAP authentication process, where user-supplied usernames are integrated into LDAP search filters and distinguished name (DN) values without proper escaping. As a result, an attacker could manipulate LDAP queries during the authentication process.
Exploitation of this vulnerability allows for LDAP injection, where an attacker can interfere with LDAP queries. This could potentially be used to bypass authentication or access unauthorized information.
Users can upgrade to WeKan version 8.19 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.