CVE-2012-3471

EUVD-2012-3427
Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) application/controllers/members/reports.php in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via an incident id.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
Affected Products (NVD)
VendorProductVersion
ushahidiushahidi_platform
𝑥
≤ 2.4.1
ushahidiushahidi_platform
1.0
ushahidiushahidi_platform
1.2
ushahidiushahidi_platform
2.0
ushahidiushahidi_platform
2.1
ushahidiushahidi_platform
2.2
ushahidiushahidi_platform
2.2.1
ushahidiushahidi_platform
2.3.1
ushahidiushahidi_platform
2.3.2
ushahidiushahidi_platform
2.4
𝑥
= Vulnerable software versions