When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52685 | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 24 May 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sismics
Sismics teedy |
|
| CPEs | cpe:2.3:a:sismics:teedy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sismics
Sismics teedy |
Mon, 10 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-90 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-10T22:11:34.342Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-54852
Updated: 2025-02-03T18:33:31.852Z
Status : Analyzed
Published: 2025-01-29T22:15:29.723
Modified: 2025-05-24T01:14:43.543
Link: CVE-2024-54852
No data.
OpenCVE Enrichment
No data.
EUVD