evergreen-ils
Enterprise Softwareoss-project
Top products
Latest CVEs
The 3 most recently published vulnerabilities affecting evergreen-ils.
- CVE-2015-2204Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by lever...7.5
- CVE-2015-2203Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a control...6.5
- CVE-2013-7435The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user...6.5