CVE-2013-10013 describes a critical SQL injection vulnerability in the Bricco Authenticator Plugin, specifically within the authenticate/compare function of the DBAuthenticator.java file. This flaw allows an unauthenticated attacker to execute arbitrary SQL commands, leading to complete compromise of confidentiality, integrity, and availability, as reflected by its CVSSv3.1 score of 9.8. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, the high FAUCET Risk Score of 79/100 indicates significant potential danger. Upgrading to version 1.39 or applying patch a5456633ff75e8f13705974c7ed1ce77f3f142d5 is recommended to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.39CPE matchmatch criteria | cpe:2.3:a:authenticator_plugin_project:authenticator_plugin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.