CVE-2013-7435
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
Affected (3)
Products: Evergreen Ils: Evergreen
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.9 |
References (14)
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Issue TrackingRelease Notes
Source: cve@mitre.org
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Timeline
No history available yet.