5.5

CVE-2009-2737

The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Toni MuellerRoundup Version1.2.0
Toni MuellerRoundup Version1.4.0
Toni MuellerRoundup Version1.4.1
Toni MuellerRoundup Version1.4.2
Toni MuellerRoundup Version1.4.3
Toni MuellerRoundup Version1.4.4
Toni MuellerRoundup Version1.4.5
Toni MuellerRoundup Version1.4.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.32% 0.812
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:N/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=518768
http://issues.roundup-tracker.org/issue2550521
http://secunia.com/advisories/34192
Vendor Advisory
http://www.debian.org/security/2009/dsa-1754
Patch
http://www.osvdb.org/56368
http://www.securityfocus.com/bid/34059
https://bugzilla.redhat.com/show_bug.cgi?id=489355
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00429.html
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00439.html