CVE-2013-7435: Infoleak
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fmIDL.xml.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7435?
CVE-2013-7435 has a moderate severity level as it allows unauthorized access to sensitive settings history information.
How do I fix CVE-2013-7435?
To fix CVE-2013-7435, upgrade Evergreen ILS to version 2.5.9, 2.6.7, or 2.7.4 or later.
What versions of Evergreen ILS are affected by CVE-2013-7435?
CVE-2013-7435 affects versions of Evergreen ILS prior to 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4.
Can CVE-2013-7435 lead to data breaches?
Yes, CVE-2013-7435 can potentially lead to data breaches by exposing sensitive settings to attackers.
Is user intervention required to exploit CVE-2013-7435?
No, CVE-2013-7435 can be exploited remotely without user intervention due to the lack of permission checks.