SQL Injection Vulnerability in CiviCRM Affected by Quick Search API
CVE-2013-4662

Currently unrated

Key Information:

Vendor

Civicrm

Status
Vendor
CVE Published:
29 January 2014

What is CVE-2013-4662?

The Quick Search API in CiviCRM versions 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 contains a vulnerability that allows remote authenticated users to bypass necessary validation mechanisms. By sending a crafted request directly to the API's second layer, an attacker can exploit SQL injection vulnerabilities, potentially leading to unauthorized access to database information and compromise the integrity of the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.