CVE-2012-3473
EUVD-2012-342912.08.2012, 21:55
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ushahidi | ushahidi_platform | 𝑥 ≤ 2.4.1 |
| ushahidi | ushahidi_platform | 1.0 |
| ushahidi | ushahidi_platform | 1.2 |
| ushahidi | ushahidi_platform | 2.0 |
| ushahidi | ushahidi_platform | 2.1 |
| ushahidi | ushahidi_platform | 2.2 |
| ushahidi | ushahidi_platform | 2.2.1 |
| ushahidi | ushahidi_platform | 2.3.1 |
| ushahidi | ushahidi_platform | 2.3.2 |
| ushahidi | ushahidi_platform | 2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References