VYPR
Unrated severityNVD Advisory· Published Sep 17, 2025· Updated Sep 30, 2025

CISA Thorium LDAP injection

CVE-2025-35431

Description

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.