ltb-project records
2 published records for vendor ltb-project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-12421No exploit | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a craftedltb-project · ldap tool box self service password · CWE-640 | Critical9.8 | — | 2.8% | Jun 14, 2018 |
39Monitor | CVE-2023-49032No exploit | An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information vialtb-project · self service password · CWE-94 | Critical9.8 | — | 1.2% | Dec 20, 2023 |
- CVE-2018-1242140Plan
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted
CriticalCVSS 9.8No exploitEPSS 3%ltb-project · ldap tool box self service passwordJun 14, 2018
- CVE-2023-4903239Monitor
An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via
CriticalCVSS 9.8No exploitEPSS 1%ltb-project · self service passwordDec 20, 2023