« Volver al listado

CVE-2013-2633

Estado: ModificadaMedia (5)—

Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-2633",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-21T21:55:01.003",
  "references": [
    {
      "url": "http://piwik.org/blog/2013/03/piwik-1-11/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://piwik.org/blog/2013/03/piwik-1-11/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters."
    },
    {
      "lang": "es",
      "value": "Piwik anterior a v1.11 acepta entradas desde una petición POST en lugar de una petición GET en circunstancias sin especificar, lo que puede permitir ataques para conseguir información a través del aprovechamiento de los parámetros del login."
    }
  ],
  "lastModified": "2026-06-16T23:53:44.607",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:matomo:matomo:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F93E615-6268-450D-A140-405E00B28CE6",
              "versionEndIncluding": "1.10.1"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E45F2630-A217-4F08-B36B-314AD69DD92D"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "419A5DA8-D63D-4EAC-A4D5-4B5A1B7D4286"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2891784E-0524-434C-9269-81C85C37D969"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "491C3F7C-889A-4E2A-A956-5ABB3836BAE7"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E38E65CD-4B1F-4D81-A818-6A4B0E312253"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E10E743-30FB-408C-A50B-BCAA0D750B82"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B80242D7-A09F-430A-9468-B52EBA6F6337"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF4B194B-C780-4005-A641-BCDB8A81FBE0"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C58F5320-BE2E-46D6-AFD8-BB298A10926F"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1D3535D-A8F1-42A2-BD7E-4EEFEF15C1F9"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FFB1D11-C059-4CD4-9C38-8D2A7901BC8F"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FA28DF4-8F43-4F35-9F1F-6A6C785B0CE4"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A33B1DF0-B069-4A72-A7AB-643E459FDB11"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2869144-4413-469B-A6EE-31F5180BA10F"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FACB8A22-2A07-4598-B8B6-27BC60F5E359"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B2C56AA-46BA-4C13-8BA2-6C37AF63D5B3"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F8E33B0-6C43-4A7B-9BF4-9E3BC8D58880"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B0054CC-1ADD-48B7-8174-DD867521FA58"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9C4CE48-9FE8-4FAF-A949-150038F723F2"
            },
            {
              "criteria": "cpe:2.3:a:matomo:matomo:1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "692E334C-0A16-4770-BEBE-1824CCE20642"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}