← Back

CVE-2013-7435

nvd nist
Published: Feb 1, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.

Affected (3)

1 product
Evergreen
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Evergreen Ils
Before 2.5.9
From 2.6.0 to 2.6.7
From 2.7.0 to 2.7.4

References (14)

Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch

Timeline

No history available yet.