PT-2014-2848 · Civicrm · Civicrm
Coleman Watts
+1
·
Publicado
2014-01-29
·
Atualizado
2022-05-17
·
CVE-2013-4662
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CiviCRM versions 4.2.0 through 4.2.9
CiviCRM versions 4.3.0 through 4.3.3
Description
The issue allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the Quick Search API, related to contact.getquick.
Recommendations
For CiviCRM versions 4.2.0 through 4.2.9, update to a version outside of this range to mitigate the risk.
For CiviCRM versions 4.3.0 through 4.3.3, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the Quick Search API until a patch is available.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Civicrm