CVE 5.4 MEDIUM

CISA Thorium LDAP injection_CVE-2025-35431

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.

Basic Information

ID CVE-2025-35431
Source cisa-cg
Published Sep 17, 2025 at 16:52

Affected Product

Vendor CISA
Product Thorium
Version 1.0.0
Affected Versions CISA Thorium 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.