CVE-2013-6872

NONE
Published Jan 21, 201412y ago · Modified Jun 17, 20262w ago
Find Similar
Published Jan 21, 2014 12y ago
Last Modified Jun 17, 2026 2w ago

Description

SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.

Threat Intelligence

No active exploitation signals — not in CISA KEV and no EPSS score yet.

Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-89 SQL Injection Injection

Affected Products 26

VendorProductVersionRange
o-dyncollabtive* ≤1.1
o-dyncollabtive0.1any
o-dyncollabtive0.2any
o-dyncollabtive0.2.5any
o-dyncollabtive0.3any
o-dyncollabtive0.3.5any
o-dyncollabtive0.3.6any
o-dyncollabtive0.4any
o-dyncollabtive0.4.5any
o-dyncollabtive0.4.6any
o-dyncollabtive0.4.7any
o-dyncollabtive0.4.8any
o-dyncollabtive0.4.9any
o-dyncollabtive0.4.9.1any
o-dyncollabtive0.5.1any
o-dyncollabtive0.5.5any
o-dyncollabtive0.6any
o-dyncollabtive0.6.1any
o-dyncollabtive0.6.2any
o-dyncollabtive0.6.3any
o-dyncollabtive0.6.4any
o-dyncollabtive0.6.5any
o-dyncollabtive0.7any
o-dyncollabtive0.7.5any
o-dyncollabtive0.7.6any
o-dyncollabtive1.0any

References 6

Remediation