The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2022-10-03T16:15:24

Updated: 2022-10-03T16:15:24

Reserved: 2022-10-03T00:00:00


Link: CVE-2012-3473

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-08-12T21:55:01.590

Modified: 2012-08-13T17:54:29.490


Link: CVE-2012-3473

JSON object: View

cve-icon Redhat Information

No data.

CWE