SQL Injection Vulnerability in CiviCRM Affected by Quick Search API
CVE-2013-4662
Currently unrated
What is CVE-2013-4662?
The Quick Search API in CiviCRM versions 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 contains a vulnerability that allows remote authenticated users to bypass necessary validation mechanisms. By sending a crafted request directly to the API's second layer, an attacker can exploit SQL injection vulnerabilities, potentially leading to unauthorized access to database information and compromise the integrity of the application.
