CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. It may be remotely exploitable.
CVE
CVE-2007-6714
Severity
MEDIUM
CVSS
6.8
EPSS
2.39%
Original NVD Description
DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.