Ushahidi · Ushahidi Platform · CVE-2012-3469
**Name of the Vulnerable Software and Affected Versions**
Ushahidi Platform versions prior to 2.5
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is possible through several vectors, including the messages admin functionality in application/controllers/admin/messages.php, application/libraries/api/MY Checkin Api Object.php, application/controllers/admin/messages/reporters.php, or the location API in application/libraries/api/MY Locations Api Object.php and application/models/location.php.
**Recommendations**
For versions prior to 2.5, update to version 2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoints and functionalities until a patch is available. Avoid using the vulnerable parameters in the affected API endpoints until the issue is resolved.