{"id":"CVE-2013-4662","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-4662","summary":"The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a…","details":"The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the \"second layer\" of the API, related to contact.getquick.","published":"2014-01-29T18:55:26.637","modified":"2026-06-16T23:57:40.930","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"http://issues.civicrm.org/jira/browse/CRM-12765"},{"type":"ADVISORY","url":"https://civicrm.org/advisory/civi-sa-2013-004-limited-sql-injection-quick-search-api"},{"type":"ADVISORY","url":"http://issues.civicrm.org/jira/browse/CRM-12765"},{"type":"ADVISORY","url":"https://civicrm.org/advisory/civi-sa-2013-004-limited-sql-injection-quick-search-api"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:57:40.930"}}