SQL Injection Vulnerability in CiviCRM Affecting Remote Access
CVE-2013-5957

Currently unrated

Key Information:

Vendor

Civicrm

Status
Vendor
CVE Published:
27 November 2013

What is CVE-2013-5957?

Prior to version 4.2.12 of CiviCRM, multiple SQL injection vulnerabilities were discovered in the AJAX handling of the Location.php file. Remote attackers could exploit these flaws via the '_value' parameter in the ajax/jqState or ajax/jqcounty endpoints, allowing them to execute arbitrary SQL queries on the database, potentially compromising sensitive information and affecting the integrity of the system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.