A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow an unauthenticated remote attacker to bypass username verification.
CVE ID: CVE-2024-56841
CVSS Base Severity: HIGH
CVSS Base Score: 7.4
Vendor: Siemens
Product: Mendix LDAP
EPSS Score: 0.09% (probability of being exploited)
EPSS Percentile: 40.74% (scored less or equal to compared to others)
EPSS Date: 2025-02-12 (when was this score calculated)