6.4
CVE-2012-3473
- EPSS 2.33%
- Veröffentlicht 12.08.2012 21:55:01
- Zuletzt bearbeitet 16.06.2026 23:43:17
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ushahidi ≫ Ushahidi Platform Version <= 2.4.1
Ushahidi ≫ Ushahidi Platform Version1.0
Ushahidi ≫ Ushahidi Platform Version1.2
Ushahidi ≫ Ushahidi Platform Version2.0
Ushahidi ≫ Ushahidi Platform Version2.1
Ushahidi ≫ Ushahidi Platform Version2.2
Ushahidi ≫ Ushahidi Platform Version2.2.1
Ushahidi ≫ Ushahidi Platform Version2.3.1
Ushahidi ≫ Ushahidi Platform Version2.3.2
Ushahidi ≫ Ushahidi Platform Version2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.33% | 0.813 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://openwall.com/lists/oss-security/2012/08/09/5
https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4
https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad