tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)
References
Configurations
No configuration.
History
27 Mar 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-497 |
Information
Published : 2024-05-19 19:15
Updated : 2025-03-27 20:15
NVD link : CVE-2024-36070
Mitre link : CVE-2024-36070
CVE.ORG link : CVE-2024-36070
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere