← Back to CVE List

CVE-2018-12421

Published: 2018-06-14T19:29Z
Last Modified: 2024-11-21T03:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt