VULNERABILITY INTELLIGENCE

CVE-2012-3473

CVSS score6.4 MEDIUM
EPSS probability2.33%
CISA KEVNot currently listed
Published2012-08-12
Last modified2026-06-16

Description

The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.