First published: Sat Dec 27 2014(Updated: )
The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenticated users to obtain sensitive birthday, displayname, firstname, and surname information via a birthdays action to api/contacts, aka bug 29315.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | =7.2.0 | |
Open-Xchange App Suite Backend | =7.2.1 | |
Open-Xchange App Suite Backend | =7.2.2 | |
Open-Xchange App Suite Backend | =7.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6241 has a high severity rating as it allows unauthorized access to sensitive birthday information.
To fix CVE-2013-6241, upgrade Open-Xchange App Suite to version 7.2.2-rev25 or later, or 7.4.0-rev14 or later.
Users of Open-Xchange App Suite versions 7.2.0, 7.2.1, 7.2.2, and 7.4.0 are affected by CVE-2013-6241.
CVE-2013-6241 can be exploited by remote authenticated users to access sensitive birthday data through improper SQL query construction.
There is no official workaround for CVE-2013-6241; applying the latest patch is the recommended solution.