Sploitus

CVE-2013-0233

2 known exploits for CVE-2013-0233

Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.

Affected products
Devise
Plataformatec Devise
= 1.5.0, 1.5.1, 1.5.2, 1.5.3, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.2.0, 2.2.1, 2.2.2
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
14.1% (96th percentile)
Weakness
CWE-399
NVD status
Modified
Published
2013-04-25
CVE-2013-0233 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2013-0233

Proof-of-concept code and exploit modules indexed by Sploitus