CVE-2013-1814 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 73.8% (pctl 99)
Patch early
A public exploit exists.
Description
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
| EPSS | 73.82% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-03-14 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | rave |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Rave 0.11 < 0.20 - User Information Disclosure | 2013-03-13 |
References
→ the Explorer · watch your stack · NVD