Impact
The Auth0 AD/LDAP Connector improperly encodes data that appears in search results and in updater log entries displayed in the admin panel, allowing an attacker to insert JavaScript code. An authenticated user with permission to modify directory attributes, or even a low‑privileged local user on the underlying host, can place malicious script content into the connector’s data store. When an administrator views the affected search results or update logs, the injected script executes in the admin’s browser, potentially exposing sensitive information, hijacking the admin session, or performing further attacks against users of the application.
Affected Systems
Auth0 AD/LDAP Connector (any release prior to version 7.0.0) is impacted. The vulnerability applies to all installations of this connector where user‑controlled data is shown in the admin panel via search results or log output.
Risk and Exploitability
The CVSS score is 9.0, indicating critical risk. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The most likely attack vector is through an authenticated user with attribute‑write privileges, or a local user on the host who can alter connector data. Once exploited, the attacker can run code in the context of administrators who view the vulnerable interface, leading to compromise of privileged accounts.
OpenCVE Enrichment