SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-6404

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2)…

MEDIUM 4.0EPSS 2.06%

Does this matter?

Lower severity and a low EPSS score (2.06%). Track it; it rarely justifies an emergency change on its own.

Description

Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
2.06% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
quassel-irc/quassel irc
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.