The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2018-02-01T17:00:00
Updated: 2024-08-06T18:09:16.651Z
Reserved: 2015-03-03T00:00:00
Link: CVE-2013-7435

No data.

Status : Modified
Published: 2018-02-01T17:29:00.367
Modified: 2024-11-21T02:00:59.497
Link: CVE-2013-7435

No data.