CWE-90

CWE-90 · 4 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-90, highest CVSS first.

  1. MEDIUM 4.3CVE-2026-101145

    A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The atta…

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-90979

    LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-49469public PoC

    GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-67223public PoC

    RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into user_dn_pattern w…

    AI risk analysis on Exploit-DB.ai →