Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-4661
HistoryJan 29, 2014 - 6:55 p.m.

Design/Logic Flaw

2014-01-2918:55:00
PRIOn knowledge base
www.prio-n.com

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.8%

CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the “access CiviCRM” permission to bypass intended access restrictions, as demonstrated by accessing custom contribution data without having the “access CiviContribute” permission.

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.8%

Related for PRION:CVE-2013-4661