CVE-2015-2203: Evergreen-Ils Evergreen

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.

Affected products

  • Evergreen-Ils Evergreen: version 2.5.9 only; version 2.6.7 only; version 2.7.4 only

Published 2018-02-01. Last modified 2026-06-17.