{"id":"CVE-2013-4662","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-4662","summary":"CiviCRM SQL injection vulnerability via Quick Search API","details":"The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the \"second layer\" of the API, related to contact.getquick.","published":"2022-05-17T04:52:06Z","modified":"2023-11-08T03:57:24.206289Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"civicrm/civicrm-core","fixedVersion":"4.2.9"},{"ecosystem":"Packagist","name":"civicrm/civicrm-core","fixedVersion":"4.3.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4662"},{"type":"WEB","url":"https://civicrm.org/advisory/civi-sa-2013-004-limited-sql-injection-quick-search-api"},{"type":"PACKAGE","url":"https://github.com/civicrm/civicrm-core"},{"type":"WEB","url":"https://issues.civicrm.org/jira/browse/CRM-12765"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:24.206289Z"}}