CVE-2013-2050

Red Hat CloudForms 5.1 / ManageIQ <=5.0 SQL Injection via miq_policy Profile

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-2050. Includes Metasploit module auxiliary/admin/http/cfme_manageiq_evm_pass_reset.

AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability (CVE-2013-2050) in Red Hat CloudForms Management Engine 5.1 to reset the password of a target account. It supports both newer and older password schema versions.

Description

SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/cfme_manageiq_evm_pass_reset.rb

This Metasploit module exploits a SQL injection vulnerability (CVE-2013-2050) in Red Hat CloudForms Management Engine 5.1 to reset the password of a target account. It supports both newer and older password schema versions.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Red Hat CloudForms Management Engine 5.1 (ManageIQ Enterprise Virtualization Manager 5.0 and earlier)
Auth required
Prerequisites: Valid credentials for initial authentication · Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56181
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64524
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89984
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=959062

Scores

EPSS 0.5416
EPSS Percentile 98.1%

Details

CWE
CWE-89
Status published
Products (2)
redhat/cloudforms_management_engine 5.1
redhat/manageiq_enterprise_virtualization_manager < 5.0
Published Jan 11, 2014
Tracked Since Feb 18, 2026