Impact
The vulnerability resides in the install.php and container-install.php scripts of openDCIM 23.04. The installer exposes LDAP configuration interfaces without enforcing proper role checks. Consequently, any authenticated user, or in some cases an unauthenticated user when REMOTE_USER is set, can alter the application’s LDAP settings.
Affected Systems
The flaw affects the openDCIM 23.04 community edition. Any deployment that includes the specified commit 4467e9c4 and retains the default install.php and container-install.php files is vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 9.3 assigns the vulnerability a critical rating. With an EPSS of 45% the probability that exploitation occurs or will occur in the near term is high. The vulnerability is not listed in the CISA KEV catalog. Attackers can modify configuration files, specifically LDAP settings, through the web interface, and in environments where REMOTE_USER is enabled without authentication, no credentials are required to access the endpoint.
OpenCVE Enrichment