CVE-2013-6931: SQL Injection
Published Jan 29, 2014
·Updated
SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.
Affected Software
3 affected components
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Event History
Jan 29, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·05:37 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6931?
CVE-2013-6931 is classified as a medium severity vulnerability due to its potential for executing arbitrary SQL commands.
2
How do I fix CVE-2013-6931?
To fix CVE-2013-6931, upgrade Cybozu Garoon to version 3.7.3 or later.
3
Who is affected by CVE-2013-6931?
CVE-2013-6931 affects remote authenticated users of Cybozu Garoon versions 3.7.0, 3.7.1, and 3.7.2.
4
What type of vulnerability is CVE-2013-6931?
CVE-2013-6931 is an SQL injection vulnerability that allows unauthorized access to the database.
5
Are there any known exploits for CVE-2013-6931?
While no specific exploits are publicly documented, the nature of SQL injection suggests potential risks if the vulnerability is exploited.