« Volver al listado

CVE-2012-3474

Estado: ModificadaMedia (5)—

The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author of a comment via an API function call.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-3474",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-12T21:55:01.637",
  "references": [
    {
      "url": "http://openwall.com/lists/oss-security/2012/08/09/5",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/ushahidi/Ushahidi_Web/commit/529f353",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2012/08/09/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/ushahidi/Ushahidi_Web/commit/529f353",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author of a comment via an API function call."
    },
    {
      "lang": "es",
      "value": "La API de comentarios en application/libraries/api/MY_Comments_Api_Object.php en la Plataforma de Ushahidi antes de v2.5 permite a atacantes remotos obtener información sensible acerca de la dirección de correo electrónico, la dirección IP, y otros atributos del autor de un comentario a través de una llamada a una función de la API.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:43:17.777",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "984B26E4-C672-46DF-B26B-8CAAEDBDFEB0",
              "versionEndIncluding": "2.4.1"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86468BDD-17C2-49CC-A488-F38CC8630979"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8EBC5A6-4FB0-4385-8299-5D6298977534"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "826225E4-F4F8-4FB6-AFAF-23CD6720CE5E"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6754F1ED-E827-433C-8F50-71F04293EEB1"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B1BC250-09BC-4051-ABEE-8B8FE1558279"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D260CD2-5483-48D2-87B9-C0298F5F2B23"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "489F7397-CF33-42C5-AF46-956D5692C6D1"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1C84D59-409A-4E73-A65A-8B12594B61DF"
            },
            {
              "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A004E65-AFA7-4551-BA2B-8EF9450B0684"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}