CVE-2013-2633

Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
matomomatomo
𝑥
≤ 1.10.1
matomomatomo
1.0
matomomatomo
1.1
matomomatomo
1.1.1
matomomatomo
1.2
matomomatomo
1.2.1
matomomatomo
1.3
matomomatomo
1.4
matomomatomo
1.5
matomomatomo
1.5.1
matomomatomo
1.6
matomomatomo
1.7
matomomatomo
1.7.1
matomomatomo
1.8
matomomatomo
1.8.1
matomomatomo
1.8.2
matomomatomo
1.8.3
matomomatomo
1.8.4
matomomatomo
1.9.1
matomomatomo
1.9.2
matomomatomo
1.10
𝑥
= Vulnerable software versions