CVE-2012-3473
Estado: ModificadaMedia (6.4)—
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.33%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- http://openwall.com/lists/oss-security/2012/08/09/5
- https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4
- https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad
- http://openwall.com/lists/oss-security/2012/08/09/5
- https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4
- https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-3473",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-08-12T21:55:01.590",
"references": [
{
"url": "http://openwall.com/lists/oss-security/2012/08/09/5",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4",
"tags": [
"Exploit",
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://openwall.com/lists/oss-security/2012/08/09/5",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions."
},
{
"lang": "es",
"value": "El (1) Informe de la API y (2) la característica de administración de la API de comentarios en la plataforma de Ushahidi anterior a v2.5, no requieren de autenticación, lo que permite a atacantes remotos generar informes y organizar los comentarios a través de funciones de la API."
}
],
"lastModified": "2026-06-16T23:43:17.680",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "984B26E4-C672-46DF-B26B-8CAAEDBDFEB0",
"versionEndIncluding": "2.4.1"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86468BDD-17C2-49CC-A488-F38CC8630979"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8EBC5A6-4FB0-4385-8299-5D6298977534"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "826225E4-F4F8-4FB6-AFAF-23CD6720CE5E"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6754F1ED-E827-433C-8F50-71F04293EEB1"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B1BC250-09BC-4051-ABEE-8B8FE1558279"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D260CD2-5483-48D2-87B9-C0298F5F2B23"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "489F7397-CF33-42C5-AF46-956D5692C6D1"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1C84D59-409A-4E73-A65A-8B12594B61DF"
},
{
"criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A004E65-AFA7-4551-BA2B-8EF9450B0684"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}