Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

miniOrange LDAP Integration security vulnerabilities

mySites.guru tracks 2 vulnerabilities in com_miniorange_dirsync. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

HighCVE-2026-780742026-08-31

miniOrange LDAP Integration (com_miniorange_dirsync) free edition 1.0.0 to 6.4.7 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login (free)", at the CVE's stated affected range 1.0.0-6.4.7. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange LDAP Integration to 6.4.8 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 6.4.8 with that release date. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 6.4.7

Full advisory: www.cve.org

HighCVE-2023-237492023-01-17

LDAP Integration with Active Directory and OpenLDAP (com_miniorange_dirsync) <= 5.0.2 - Unauthenticated LDAP Injection

The miniOrange "LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login" extension does not sanitise the username POST parameter before building the LDAP query, so an unauthenticated attacker can inject LDAP filter syntax at the login form and dump arbitrary contents from the directory (CVE-2023-23749, CVSS 3.1 7.5 HIGH, AV:N/AC:L/PR:N/UI:N). The Joomla CNA records 5.0.2 as affected and 6.0.0 as unaffected; 5.0.2 is the only version the CNA tested, so this rule flags 5.0.2 and anything below it, which is the safe superset. The extension installs as a bundle whose component, System plugin (miniorangedirsync) and Authentication plugin (moldap) all carry the same version number, so the component version is a reliable indicator of the bundle version even though the injection itself is in the authentication path. Update to 6.0.0 or later.

Affected versions: ≤ 5.0.2

Full advisory: extensions.joomla.org

Running miniOrange LDAP Integration on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-78074, CVE-2023-23749. Rules current as of 13 September 2026.