Description
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin Two Factor Authentication Cross-Site Scripting (1.0.7)
Zenphoto Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-36079)
Oracle Database Server CVE-2022-21393 Vulnerability (CVE-2022-21393)
WordPress Plugin Watu Quiz Cross-Site Scripting (3.1.2.5)
WordPress Plugin Print Invoice & Delivery Notes for WooCommerce Cross-Site Scripting (4.7.1)