CVE-2013-7435

The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*
cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*
cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:18

Type Values Removed Values Added
References
  • {'url': 'http://git.evergreen-ils.org/?p=Evergreen.git;a=commit;h=ac588e879cf73ff1b65617e0bd273361d3529063', 'name': 'http://git.evergreen-ils.org/?p=Evergreen.git;a=commit;h=ac588e879cf73ff1b65617e0bd273361d3529063', 'tags': ['Patch', 'Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=ac588e879cf73ff1b65617e0bd273361d3529063 -

Information

Published : 2018-02-01 17:29

Updated : 2024-02-28 16:25


NVD link : CVE-2013-7435

Mitre link : CVE-2013-7435

CVE.ORG link : CVE-2013-7435


JSON object : View

Products Affected

evergreen-ils

  • evergreen
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor