CVE detail
CVE-2009-2737 — CVE-2009-2737
Published 2009-08-11 · Modified 2026-06-16 · Vendor toni_mueller · Product roundup · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0232
EPSS probability
exploitation probability, 30d
82.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References