Impact
Drupal LDAP / Active Directory Integration contains an LDAP Injection flaw caused by improper neutralization of special elements in LDAP queries, which allows attackers to inject arbitrary LDAP statements. The vulnerability can lead to the unauthorized disclosure of directory information, potentially exposing sensitive organizational data for sites that rely on LDAP authentication. Based on the description, it is inferred that the impact primarily affects confidentiality, enabling an attacker to read data not intended for public consumption.
Affected Systems
The Drupal LDAP / Active Directory Integration module is affected for all versions ranging from 0.0.0 up to and including 2.2.1. Any Drupal site that has this module installed within that version window is susceptible to attack and may expose its LDAP directory data to malicious actors.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The exploit is a classic LDAP injection that can be performed when an attacker can influence input that is incorporated into an LDAP query. Because no EPSS score is available and the issue is not listed in CISA KEV, the likelihood of widespread exploitation is currently low, but the vector remains active and could be leveraged by adversaries with the necessary access to the vulnerable forms or inputs."
OpenCVE Enrichment