CVE-2014-125054
koroket RedditOnRails Vote access control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as 7f3c7407d95d532fcc342b00d68d0ea09ca71030. It is recommended to apply a patch to fix this issue. VDB-217594 is the identifier assigned to this vulnerability.
Una vulnerabilidad fue encontrada en koroket RedditOnRails y clasificada como crítica. Código desconocido del componente Vote Handler es afectado por esta vulnerabilidad. La manipulación conduce a controles de acceso inadecuados. El ataque se puede iniciar de forma remota. El parche se identifica como 7f3c7407d95d532fcc342b00d68d0ea09ca71030. Se recomienda aplicar un parche para solucionar este problema. VDB-217594 es el identificador asignado a esta vulnerabilidad.
In koroket RedditOnRails wurde eine Schwachstelle entdeckt. Sie wurde als kritisch eingestuft. Hierbei betrifft es unbekannten Programmcode der Komponente Vote Handler. Durch die Manipulation mit unbekannten Daten kann eine improper access controls-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Patch wird als 7f3c7407d95d532fcc342b00d68d0ea09ca71030 bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-07 CVE Reserved
- 2023-01-07 CVE Published
- 2024-07-30 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.217594 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/koroket/RedditOnRails/commit/7f3c7407d95d532fcc342b00d68d0ea09ca71030 | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Reddit-on-rails Project Search vendor "Reddit-on-rails Project" | Reddit-on-rails Search vendor "Reddit-on-rails Project" for product "Reddit-on-rails" | < 2014-12-19 Search vendor "Reddit-on-rails Project" for product "Reddit-on-rails" and version " < 2014-12-19" | ruby |
Affected
|