Security Advisory

CVE-2012-3474

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-08-12 21:00:00
Last updated 2024-09-17 02:48:09
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author of a comment via an API function call.