CVE-2018-12689: phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id param ...

Severity: Critical

CVSS Score: 9.8

phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.