The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T18:09:16.651Z
Reserved: 2015-03-03T00:00:00
Link: CVE-2013-7435

No data.

Status : Modified
Published: 2018-02-01T17:29:00.367
Modified: 2024-11-21T02:00:59.497
Link: CVE-2013-7435

No data.

No data.