7.5
CVE-2012-4470
- EPSS 1.3%
- Veröffentlicht 30.11.2012 22:55:00
- Zuletzt bearbeitet 16.06.2026 23:45:09
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment authors to bypass access restrictions and possibly have other unspecified impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Philip Ludlam ≫ Listhandler Version6.x-1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.3% | 0.668 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.openwall.com/lists/oss-security/2012/10/04/3
http://drupal.org/node/1679412
http://drupal.org/node/1819780
http://www.securityfocus.com/bid/54376