CVE-2012-3473: Ushahidi Platform

Medium severity, CVSS 6.4. EPSS: 2.3% chance of exploitation in the next 30 days.

The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.

Affected products

  • Ushahidi Ushahidi Platform: up to and including 2.4.1; version 1.0 only; version 1.2 only; version 2.0 only; version 2.1 only; version 2.2 only; …

Published 2012-08-12. Last modified 2026-06-16.