LDAP Injection Vulnerability in rConfig by RConfig
CVE-2020-23148
7.5HIGH
What is CVE-2020-23148?
The rConfig product version 3.9.5 contains a vulnerability that allows attackers to manipulate the userLogin parameter in the ldap/login.php file due to a lack of proper input sanitization. This can result in LDAP injection, enabling malicious users to execute crafted POST requests to gain unauthorized access to sensitive information within the system.
