CVE-2026-25560
Discovered by AISLEPUBLISHEDCWE-90
Description
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
CVSS Base Scores
CVSS v4.08.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| WeKan | WeKan | 0 | affected |
Credits
- Joshua Rogers(finder)