Lucene search

K
nvd[email protected]NVD:CVE-2013-1245
HistoryMay 16, 2013 - 3:36 a.m.

CVE-2013-1245

2013-05-1603:36:22
CWE-20
web.nvd.nist.gov
2

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

29.8%

The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restrictions via crafted requests, aka Bug ID CSCue67190.

Affected configurations

Nvd
Node
ciscowebex_socialMatch-
VendorProductVersionCPE
ciscowebex_social-cpe:2.3:a:cisco:webex_social:-:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

29.8%

Related for NVD:CVE-2013-1245