tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-19 19:15
Updated : 2025-03-27 20:15
NVD link : CVE-2024-36070
Mitre link : CVE-2024-36070
CVE.ORG link : CVE-2024-36070
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
