High severity8.1NVD Advisory· Published Nov 6, 2020· Updated Jun 17, 2026
CVE-2020-15259
CVE-2020-15259
Description
ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF payload on the same machine that has access to the ad-ldap-connector admin console via a browser. You may be affected if you use the admin console included with ad-ldap-connector versions <=5.0.12. If you do not have ad-ldap-connector admin console enabled or do not visit any other public URL while on the machine it is installed on, you are not affected. The issue is fixed in version 5.0.13.
Affected products
3cpe:2.3:a:auth0:ad\/ldap_connector:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:auth0:ad\/ldap_connector:*:*:*:*:*:node.js:*:*range: <5.0.13
- (no CPE)range: <=5.0.12
- auth0/ad-ldap-connectorv5Range: < 0.0.1
Patches
Vulnerability mechanics
References
2- github.com/auth0/ad-ldap-connector/commit/8b793631ec5ecacf63ff3ece23231a9e138ae911nvdPatchThird Party Advisory
- github.com/auth0/ad-ldap-connector/security/advisories/GHSA-vx5q-cp9v-427vnvdThird Party Advisory
News mentions
0No linked articles in our index yet.