CVE-2013-1814
medium · 4The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
4
CVSS
73.8%
EPSS (exploit prob.)
99th
EPSS percentile
2013-03-14
Published
AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | rave | 0.11 |
| apache | rave | 0.12 |
| apache | rave | 0.13 |
| apache | rave | 0.14 |
| apache | rave | 0.15 |
| apache | rave | 0.16 |
| apache | rave | 0.17 |
| apache | rave | 0.18 |
| apache | rave | 0.19 |
| apache | rave | 0.20 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-1814