Description
This script is possibly vulnerable to LDAP Injection attacks.
Lightweight Directory Access Protocol (LDAP) is an open-standard protocol for both querying and manipulating X.500 directory services. When a web application fails to properly sanitize user-supplied input, it is possible for an attacker to alter the construction of an LDAP statement.
Remediation
Your script should filter metacharacters from user input.
References
Related Vulnerabilities
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.8)
WordPress Improper Input Validation Vulnerability (CVE-2014-9038)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2013-2185)
Jenkins Improper Input Validation Vulnerability (CVE-2018-1999002)
Moodle Improper Input Validation Vulnerability (CVE-2011-4582)