Impact
This vulnerability is an LDAP injection flaw in the sign‑in endpoint of Liderahenk that allows an attacker to supply unfiltered input, causing the server to execute malicious LDAP queries. Classified as CWE‑90, the flaw can enable an attacker to read sensitive directory entries, exfiltrate credentials, or bypass authentication requirements, leading to significant data exposure.
Affected Systems
Affected systems are TÜBİTAK BİLGEM’s Liderahenk versions from 3.4.0 through 3.5.4. The flaw resides in the sign‑in flow and impacts all deployments of these releases that rely on the default LDAP configuration.
Risk and Exploitability
The CVSS score of 7.5 marks this vulnerability as high impact. While EPSS is not published, the absence of a KEV listing indicates no known widespread exploitation to date. The likely attack vector is remote, involving crafted HTTP requests to the login service. Exploitation would require no privileged access but could be performed by an unauthenticated or low‑privilege attacker to read directory data or impersonate a user.
OpenCVE Enrichment