The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2012-08-12T21:00:00Z
Updated: 2024-09-16T16:27:36.345Z
Reserved: 2012-06-14T00:00:00Z
Link: CVE-2012-3473
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-08-12T21:55:01.590
Modified: 2024-11-21T01:40:56.977
Link: CVE-2012-3473
Redhat
No data.