VulnerabilityModified
CVE-2013-4662
The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to…
MEDIUM 6.5EPSS 1.01%
Does this matter?
Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.
Description
The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- civicrm/civicrm
- Source
- cve@mitre.org
References
- http://issues.civicrm.org/jira/browse/CRM-12765Vendor Advisory
- https://civicrm.org/advisory/civi-sa-2013-004-limited-sql-injection-quick-search-apiVendor Advisory
- http://issues.civicrm.org/jira/browse/CRM-12765Vendor Advisory
- https://civicrm.org/advisory/civi-sa-2013-004-limited-sql-injection-quick-search-apiVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.