vendor:
CITSmart ITSM
by:
skysbsb
9.8
CVSS
CRITICAL
LDAP Injection
20
CWE
Product Name: CITSmart ITSM
Affected Version From: < 9.1.2.23
Affected Version To: < 9.1.2.23
Patch Exists: YES
Related CWE: CVE-2020-35775
CPE: a:citsmart:citsmart_itsm:9.1.2.22
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
CITSmart ITSM 9.1.2.22 – LDAP Injection
To exploit this flaw it is necessary to have at least one user/password previously registered, because the system checks (ldap bind) the first user returned in the ldap search. However, it returns the last user found in the search to the function that called it (logic error). So, I call this problem an LDAP injection in conjunction with a programming logic error that allows you to authenticate to CITSmart ITSM with another valid user without needing to know the target user's password.
Mitigation:
Upgrade to version 9.1.2.23 or later