Description
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.
Remediation
References
Related Vulnerabilities
MySQL Cryptographic Issues Vulnerability (CVE-2003-1480)
WordPress Plugin Z-URL Preview Cross-Site Scripting (1.6.2)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-35611)
Moodle CVE-2022-40314 Vulnerability (CVE-2022-40314)
WordPress Plugin Nifty Newsletters (Formerly Sola Newsletters) Cross-Site Request Forgery (4.0.23)