{"api_version":"1","generated_at":"2026-07-24T21:27:48+00:00","cve":"CVE-2007-1923","urls":{"html":"https://cve.report/CVE-2007-1923","api":"https://cve.report/api/cve/CVE-2007-1923.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1923","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1923"},"summary":{"title":"CVE-2007-1923","description":"(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-04-10 23:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/38218","name":"http://osvdb.org/38218","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/464880/100/0/threaded","name":"http://www.securityfocus.com/archive/1/464880/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23352","name":"http://www.securityfocus.com/bid/23352","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SQL-Ledger/LedgerSMB Insecure User Access Restriction Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/2552","name":"http://securityreason.com/securityalert/2552","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/38217","name":"http://osvdb.org/38217","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33494","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33494","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ledgersmb/LedgerSMB/blob/master/Changelog","name":"https://github.com/ledgersmb/LedgerSMB/blob/master/Changelog","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"LedgerSMB/Changelog at master · ledgersmb/LedgerSMB · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1923","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1923","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1923","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ledgersmb","cpe5":"ledgersmb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1923","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sql-ledger","cpe5":"sql-ledger","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:13:41.559Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38218","tags":["vdb-entry","x_transferred"],"url":"http://osvdb.org/38218"},{"name":"sqlledger-acl-weak-security(33494)","tags":["vdb-entry","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33494"},{"name":"2552","tags":["third-party-advisory","x_transferred"],"url":"http://securityreason.com/securityalert/2552"},{"name":"38217","tags":["vdb-entry","x_transferred"],"url":"http://osvdb.org/38217"},{"name":"23352","tags":["vdb-entry","x_transferred"],"url":"http://www.securityfocus.com/bid/23352"},{"name":"20070406 ACLS ineffective in SQL-Ledger and LedgerSMB","tags":["mailing-list","x_transferred"],"url":"http://www.securityfocus.com/archive/1/464880/100/0/threaded"},{"tags":["x_transferred"],"url":"https://github.com/ledgersmb/LedgerSMB/blob/master/Changelog"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-04-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2023-09-25T04:58:55.612Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"38218","tags":["vdb-entry"],"url":"http://osvdb.org/38218"},{"name":"sqlledger-acl-weak-security(33494)","tags":["vdb-entry"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33494"},{"name":"2552","tags":["third-party-advisory"],"url":"http://securityreason.com/securityalert/2552"},{"name":"38217","tags":["vdb-entry"],"url":"http://osvdb.org/38217"},{"name":"23352","tags":["vdb-entry"],"url":"http://www.securityfocus.com/bid/23352"},{"name":"20070406 ACLS ineffective in SQL-Ledger and LedgerSMB","tags":["mailing-list"],"url":"http://www.securityfocus.com/archive/1/464880/100/0/threaded"},{"url":"https://github.com/ledgersmb/LedgerSMB/blob/master/Changelog"}]}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1923","datePublished":"2007-04-10T00:00:00.000Z","dateReserved":"2007-04-10T00:00:00.000Z","dateUpdated":"2024-08-07T13:13:41.559Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-04-10 23:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:*","versionEndExcluding":"1.3.0","matchCriteriaId":"0AEC949D-05C5-46A4-8524-708110C55CD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:sql-ledger:sql-ledger:-:*:*:*:*:*:*:*","matchCriteriaId":"BA6F3CE1-B130-49E4-BABB-A2C44F955625"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1923","Ordinal":"1","Title":"CVE-2007-1923","CVE":"CVE-2007-1923","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1923","Ordinal":"1","NoteData":"(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.","Type":"Description","Title":"CVE-2007-1923"},{"CveYear":"2007","CveId":"1923","Ordinal":"2","NoteData":"2007-04-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1923","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}