CVE-2013-2633: Input Validation
Published Mar 21, 2013
·Updated
Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters.
Affected Software
23 affected componentsFixes available
Matomo Matomo<=1.10.1
Matomo Matomo=1.0
Matomo Matomo=1.1
Matomo Matomo=1.1.1
Matomo Matomo=1.2
Matomo Matomo=1.2.1
Matomo Matomo=1.3
Matomo Matomo=1.4
Matomo Matomo=1.5
Matomo Matomo=1.5.1
Matomo Matomo=1.6
Matomo Matomo=1.7
Matomo Matomo=1.7.1
Matomo Matomo=1.8
Matomo Matomo=1.8.1
Matomo Matomo=1.8.2
Matomo Matomo=1.8.3
Matomo Matomo=1.8.4
Matomo Matomo=1.9.1
Matomo Matomo=1.9.2
Matomo Matomo=1.10
composer/piwik/piwik<1.11
1.11
composer/matomo/matomo<1.11
1.11
Event History
Mar 21, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-2633?
CVE-2013-2633 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2013-2633?
To fix CVE-2013-2633, upgrade to Piwik version 1.11 or later.
3
What kind of attack does CVE-2013-2633 enable?
CVE-2013-2633 may allow attackers to obtain sensitive information through improperly logged POST request parameters.
4
Which versions of Piwik are affected by CVE-2013-2633?
CVE-2013-2633 affects Piwik versions prior to 1.11, specifically from 1.0 to 1.10.1.
5
What systems are impacted by CVE-2013-2633?
CVE-2013-2633 impacts all installations of Piwik up to version 1.10.1.