CVE-2015-2203: Evergreen-Ils Evergreen
Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
Affected products
- Evergreen-Ils Evergreen: version 2.5.9 only; version 2.6.7 only; version 2.7.4 only
Published 2018-02-01. Last modified 2026-06-17.