CVE-2020-17477: Univention Ucs@school
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a teacher can gain administrator access via an NTLM hash.
Affected products
- Univention Ucs@school: up to and including 4.4
Published 2023-10-26. Last modified 2026-06-17.