Security Advisory

CVE-2012-3473

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-08-12 21:00:00
Last updated 2024-09-16 16:27:36
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.