Lucene search

K
cvelistMitreCVELIST:CVE-2013-6241
HistoryDec 27, 2014 - 6:00 p.m.

CVE-2013-6241

2014-12-2718:00:00
mitre
www.cve.org
4

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

38.7%

The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenticated users to obtain sensitive birthday, displayname, firstname, and surname information via a birthdays action to api/contacts, aka bug 29315.

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

38.7%

Related for CVELIST:CVE-2013-6241