6.4
CVSSv2

CVE-2012-3472

Published: 12/08/2012 Updated: 13/08/2012
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform prior to 2.5 does not require authentication, which allows remote malicious users to list, delete, or organize messages via a GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

ushahidi ushahidi platform 2.4

ushahidi ushahidi platform 2.3.1

ushahidi ushahidi platform 1.2

ushahidi ushahidi platform 2.2.1

ushahidi ushahidi platform 2.2

ushahidi ushahidi platform 2.1

ushahidi ushahidi platform 2.0

ushahidi ushahidi platform

ushahidi ushahidi platform 2.3.2

ushahidi ushahidi platform 1.0