CVE-2013-5957

CiviCRM < 4.2.12, 4.3.x < 4.3.7, 4.4.x < 4.4.beta4 - SQL Injection via _value Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, and 4.4.x before 4.4.beta4 allow remote attackers to execute arbitrary SQL commands via the _value parameter to (1) ajax/jqState or (2) ajax/jqcounty.

Scores

EPSS 0.0209
EPSS Percentile 79.6%

Details

CWE
CWE-89
Status published
Products (20)
civicrm/civicrm 4.4 alpha3 (4 CPE variants)
civicrm/civicrm 4.4.0 alpha1 (2 CPE variants)
civicrm/civicrm 4.2.0
civicrm/civicrm 4.2.1
civicrm/civicrm 4.2.2
civicrm/civicrm 4.2.4
civicrm/civicrm 4.2.5
civicrm/civicrm 4.2.6
civicrm/civicrm 4.2.7
civicrm/civicrm 4.2.8
... and 10 more
Published Nov 27, 2013
Tracked Since Feb 18, 2026