SQL Injection Vulnerability in CiviCRM Affecting Remote Access
CVE-2013-5957
Currently unrated
What is CVE-2013-5957?
Prior to version 4.2.12 of CiviCRM, multiple SQL injection vulnerabilities were discovered in the AJAX handling of the Location.php file. Remote attackers could exploit these flaws via the '_value' parameter in the ajax/jqState or ajax/jqcounty endpoints, allowing them to execute arbitrary SQL queries on the database, potentially compromising sensitive information and affecting the integrity of the system.
