VYPR
Unrated severityNVD Advisory· Published Oct 11, 2013· Updated Apr 29, 2026

CVE-2013-4137

CVE-2013-4137

Description

Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."

Affected products

3
  • Status/Statusnet3 versions
    cpe:2.3:a:status:statusnet:1.0.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:status:statusnet:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:status:statusnet:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:status:statusnet:1.1.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.