In VeridiumID before 3.5.0, the identity provider page allows an unauthenticated attacker to discover information about registered users via an LDAP injection attack.
CVSS
No CVSS.
References
Configurations
History
16 Apr 2025, 15:03
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:veridiumid:veridiumad:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Veridiumid veridiumad
Veridiumid |
|
References | () https://veridiumid.com/veridium-id-authentication-platform/ - Product | |
References | () https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement - Vendor Advisory |
03 Apr 2024, 17:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-03 17:15
Updated : 2025-04-16 15:03
NVD link : CVE-2023-44038
Mitre link : CVE-2023-44038
JSON object : View
Products Affected
veridiumid
- veridiumad
CWE