CVE-2009-2737

medium

Description

The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.

References

https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00439.html

https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00429.html

https://bugzilla.redhat.com/show_bug.cgi?id=489355

http://www.securityfocus.com/bid/34059

http://www.osvdb.org/56368

http://www.debian.org/security/2009/dsa-1754

http://secunia.com/advisories/34192

http://issues.roundup-tracker.org/issue2550521

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=518768

Details

Source: Mitre, NVD

Published: 2009-08-11

Updated: 2009-08-26

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity: Medium