This module enables users to authenticate using LDAP or Active Directory credentials.
The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.