CVE-2013-6241
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenticated users to obtain sensitive birthday, displayname, firstname, and surname information via a birthdays action to api/contacts, aka bug 29315.
El widget de Cumpleaños en el 'backend' en Open-Xchange (OX) AppSuite 7.2.x anterior a 7.2.2-rev25 y 7.4.x anterior a 7.4.0-rev14, en algunos casos de compartición de identidad de usuario, no construye adecuadamente una sentencia SQL para los cumpleaños del año siguiente, lo que permite a usuarios remotos autenticados obtener información sensible de cumpleaños, información del nombre a mostrar, nombre, y apellidos a través de la acción cumpleaños en api/contacts, también conocido como bug 29315
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-10-22 CVE Reserved
- 2013-11-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-11/0025.html | Mailing List | |
https://forum.open-xchange.com/showthread.php?8059-Open-Xchange-releases-Security-Patch-2013-10-21-for-v7-2-2-and-v7-4-0 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.2.0 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.0" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.2.1 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.1" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.2.2 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.2.2" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.4.0 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.4.0" | - |
Affected
|