CVE-2015-2203
01.02.2018, 17:29
Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.Enginsight
Vendor | Product | Version |
---|---|---|
evergreen-ils | evergreen | 2.5.9 |
evergreen-ils | evergreen | 2.6.7 |
evergreen-ils | evergreen | 2.7.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References