SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4661

CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intended…

MEDIUM 4.9EPSS 0.99%

Does this matter?

Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.

Description

CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intended access restrictions, as demonstrated by accessing custom contribution data without having the "access CiviContribute" permission.

CVSS 2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
EPSS
0.99% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
civicrm/civicrm
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.