CVE-2013-4662
CiviCRM 4.2.0-4.2.9 and 4.3.0-4.3.3 - Authenticated SQL Injection via Quick Search API
Title source: llmDescription
The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://civicrm.org/advisory/civi-sa-2013-004-limited-sql-injection-quick-search-api
Vendor Advisory x_refsource_confirm
http://issues.civicrm.org/jira/browse/CRM-12765
Scores
EPSS
0.0101
EPSS Percentile
59.7%
Details
CWE
CWE-89
Status
published
Products (14)
civicrm/civicrm
4.2.0
civicrm/civicrm
4.2.1
civicrm/civicrm
4.2.2
civicrm/civicrm
4.2.4
civicrm/civicrm
4.2.5
civicrm/civicrm
4.2.6
civicrm/civicrm
4.2.7
civicrm/civicrm
4.2.8
civicrm/civicrm
4.2.9
civicrm/civicrm
4.3.0
... and 4 more
Published
Jan 29, 2014
Tracked Since
Feb 18, 2026