CVE-2013-4789

high
Published 2013-08-09 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/Cotonti/Cotonti/commit/45eec046391afabb676b62b9201da0cd530360b4

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.cotonti.com/news/announce/siena_0914_released

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/54289

Application impact

VendorProductVersionsFixed
cotonticotonti_siena{"endIncluding":"0.9.13"}
cotonticotonti_siena0.9.0
cotonticotonti_siena0.9.1
cotonticotonti_siena0.9.2
cotonticotonti_siena0.9.3
cotonticotonti_siena0.9.4
cotonticotonti_siena0.9.5
cotonticotonti_siena0.9.6
cotonticotonti_siena0.9.7
cotonticotonti_siena0.9.8
cotonticotonti_siena0.9.9
cotonticotonti_siena0.9.10
cotonticotonti_siena0.9.11
cotonticotonti_siena0.9.12

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.