CVE-2013-4662

The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
civicrmcivicrm
4.2.0
civicrmcivicrm
4.2.1
civicrmcivicrm
4.2.2
civicrmcivicrm
4.2.4
civicrmcivicrm
4.2.5
civicrmcivicrm
4.2.6
civicrmcivicrm
4.2.7
civicrmcivicrm
4.2.8
civicrmcivicrm
4.2.9
civicrmcivicrm
4.3.0
civicrmcivicrm
4.3.1
civicrmcivicrm
4.3.2
civicrmcivicrm
4.3.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
civicrm
bullseye
5.33.2+dfsg1-1
fixed
sid
5.68.1+dfsg1-1
fixed