peter bassill · operator
$ cve CVE-2013-1814 JSON

CVE-2013-1814 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 73.8% (pctl 99)

Patch early

A public exploit exists.

Description

The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS73.82% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2013-03-14
Last modified2026-06-16

Affected (1)

VendorProduct
apacherave

Public exploits

SourceTitleDate
exploit-dbApache Rave 0.11 < 0.20 - User Information Disclosure2013-03-13

References

→ the Explorer  ·  watch your stack  ·  NVD