PT-2012-4741 · Ushahidi · Ushahidi Platform

Dennison Williams

+1

·

Publicado

2012-08-12

·

Atualizado

2012-08-13

·

CVE-2012-3472

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ushahidi Platform versions prior to 2.5
Description The issue concerns the email API in the Ushahidi Platform, which does not require authentication. This allows remote attackers to list, delete, or organize messages via a GET request to the API endpoint.
Recommendations For versions prior to 2.5, consider requiring authentication for the email API to prevent unauthorized access. As a temporary workaround, restrict access to the email API endpoint to minimize the risk of exploitation.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3472

Produtos afetados

Ushahidi Platform