CVE-2013-7435
Summary
| CVE | CVE-2013-7435 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-01 17:29:00 UTC |
| Updated | 2023-11-07 02:18:00 UTC |
| Description | The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Evergreen-ils | Evergreen | All | All | All | All |
| Application | Evergreen-ils | Evergreen | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7 | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| Bug #1206589 “Credit Card Processor settings visible in LSE Hist...” : Bugs : Evergreen | CONFIRM | bugs.launchpad.net | Issue Tracking, Patch |
| git.evergreen-ils.org Git - Evergreen.git/commit | CONFIRM | git.evergreen-ils.org | Patch, Vendor Advisory |
| SECURITY RELEASES: Evergreen 2.7.4, 2.6.7, and 2.5.9 – Evergreen ILS | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4 | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9 | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| oss-security - Re: CVE request - Evergreen | MLIST | www.openwall.com | Issue Tracking, Mailing List, Third Party Advisory |
| git.evergreen-ils.org Git | git.evergreen-ils.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.