5.3
CVE-2012-2724
- EPSS 2.45%
- Veröffentlicht 09.01.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:39:30
- Erkennungen
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Md-systems ≫ Simplenews Version 6.x-1.0 Update - SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update beta1 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update beta2 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update beta3 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update beta4 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update beta5 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update rc1 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update rc2 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update rc3 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update rc4 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update rc5 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.0 Update rc6 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.1 Update - SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.2 Update - SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-1.3 Update - SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-2.0 Update alpha1 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-2.0 Update alpha2 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-2.0 Update alpha3 SwPlatform drupal
Md-systems ≫ Simplenews Version 6.x-2.x Update dev SwPlatform drupal
Md-systems ≫ Simplenews Version 7.x-1.0 Update - SwPlatform drupal
Md-systems ≫ Simplenews Version 7.x-1.0 Update alpha1 SwPlatform drupal
Md-systems ≫ Simplenews Version 7.x-1.0 Update alpha2 SwPlatform drupal
Md-systems ≫ Simplenews Version 7.x-1.0 Update beta1 SwPlatform drupal
Md-systems ≫ Simplenews Version 7.x-1.0 Update beta2 SwPlatform drupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.45% | 0.823 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.openwall.com/lists/oss-security/2012/06/14/3
http://drupal.org/node/1619812
http://drupal.org/node/1619818
http://drupal.org/node/1619820
http://drupal.org/node/1619848
http://drupalcode.org/project/simplenews.git/commitdiff/36352c1
http://drupalcode.org/project/simplenews.git/commitdiff/6d5704c
http://drupalcode.org/project/simplenews.git/commitdiff/faec6a6
http://www.securityfocus.com/bid/53839
https://exchange.xforce.ibmcloud.com/vulnerabilities/76143