Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4662

Опубликовано: 29 янв. 2014
Источник: debian
EPSS Низкий

Описание

The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
civicrmnot-affectedpackage

EPSS

Процентиль: 33%
0.00132
Низкий

Связанные уязвимости

nvd
около 12 лет назад

The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.

github
больше 3 лет назад

CiviCRM SQL injection vulnerability via Quick Search API

EPSS

Процентиль: 33%
0.00132
Низкий