The ad-ldap-connector admin console does not provide CSRF protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF payload on the same machine that has access to the ad-ldap-connector admin console via a browser.
You may be affected if you use the admin console included with ad-ldap-connector versions <=5.0.12.If you do not have ad-ldap-connector admin console enabled or do not visit any other public URL while on the machine it is installed on, you are not affected.