CVE-2024-54852

When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:sismics:teedy:*:*:*:*:*:*:*:*

History

24 May 2025, 01:14

Type Values Removed Values Added
First Time Sismics teedy
Sismics
References () https://github.com/Tanguy-Boisset/CVE/blob/master/CVE-2024-54852/README.md - () https://github.com/Tanguy-Boisset/CVE/blob/master/CVE-2024-54852/README.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:sismics:teedy:*:*:*:*:*:*:*:*

29 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 22:15

Updated : 2025-05-24 01:14


NVD link : CVE-2024-54852

Mitre link : CVE-2024-54852


JSON object : View

Products Affected

sismics

  • teedy
CWE

No CWE.