Conduct input sanitization: The primary safeguard against LDAP injection is to validate and cleanse all user-supplied inputs before they're incorporated into LDAP queries. By enforcing strict whitelists (allowing only expected characters or patterns) and escaping or rejecting any special LDAP-filter metacharacters, you eliminate the injection vectors at the source. Deploy a WAF: While you're remediating the code, a properly configured Web Application Firewall can provide an additional layer of defense by detecting and blocking known LDAP injection payloads (e.g., *)(uid=*))(|(uid=*) in incoming requests. This helps mitigate exploitation risk in the short term and serves as a compensating control until the application is fully secured.