LDAP - Critical - Data Injection

* Advisory ID: DRUPAL-SA-CONTRIB-2017-052
* Project: Lightweight Directory Access Protocol (LDAP) (third-party module)
* Version: 7.x
* Date: 2017-May-31
* Security risk: 15/25 ( Critical)
* Vulnerability: Multiple vulnerabilities

DESCRIPTION

The LDAP module does not sanitize user input correctly in several cases,
allowing a user to modify parameters without restriction and inject data.

If the site administrator chooses to hide the email or password from the user
form (instead of showing or disabling it under "Authorization"), these values
can be overwritten.

VERSIONS AFFECTED

* LDAP 7.x-2.x versions prior to 7.x-2.2.

Drupal core is not affected. If you do not use the contributed Lightweight
Directory Access Protocol (LDAP) module, there is nothing you need to
do.

SOLUTION

Install the latest version:

* If you use the LDAP module for Drupal 7.x-2.x, upgrade to LDAP-7.x-2.2

Also see the Lightweight Directory Access Protocol (LDAP) project page: https://www.drupal.org/project/ldap

Add new comment