Insufficiently Protected Credentials in the AD/LDAP...
Moderate severity
Unreviewed
Published
Jan 20, 2023
to the GitHub Advisory Database
•
Updated Feb 10, 2023
Description
Published by the National Vulnerability Database
Jan 20, 2023
Published to the GitHub Advisory Database
Jan 20, 2023
Last updated
Feb 10, 2023
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.
References