PoC Index

CVE-2013-0233

MEDIUM 6.8EPSS 14.1%

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
14.13% chance of exploitation in the next 30 days, 96th percentile
Published
2013-04-25
Updated
2024-09-17

Metasploit modules (1)

References

Related