stable
Clone or download
Read-only
request #24149: Indirect LDAP injection via the ldap_id attribute of a user
A taint annotation has been added to hightlight the issue. A more global work on this topic will be done in independant contributions. Change-Id: I969d0ba6d2ff85b418bcaf728f49afc78dd49571
Modified Files
Name | ||||
---|---|---|---|---|
M | plugins/ldap/include/LDAP_DirectorySynchronization.class.php | +1 | −1 | Go to diff View file |
M | src/common/DB/Compat/Legacy2018/LegacyDataAccessInterface.php | +1 | −0 | Go to diff View file |