PT-2012-4741 · Ushahidi · Ushahidi Platform
Dennison Williams
+1
·
Publicado
2012-08-12
·
Atualizado
2012-08-13
·
CVE-2012-3472
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ushahidi Platform versions prior to 2.5
Description
The issue concerns the email API in the Ushahidi Platform, which does not require authentication. This allows remote attackers to list, delete, or organize messages via a GET request to the API endpoint.
Recommendations
For versions prior to 2.5, consider requiring authentication for the email API to prevent unauthorized access. As a temporary workaround, restrict access to the email API endpoint to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ushahidi Platform