Vulnerability Description
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Md-Systems | Simplenews | 6.x-1.0 |
Related Weaknesses (CWE)
References
- http://drupal.org/node/1619812Third Party Advisory
- http://drupal.org/node/1619818Third Party Advisory
- http://drupal.org/node/1619820Third Party Advisory
- http://drupal.org/node/1619848Third Party Advisory
- http://drupalcode.org/project/simplenews.git/commitdiff/36352c1Permissions RequiredThird Party Advisory
- http://drupalcode.org/project/simplenews.git/commitdiff/6d5704cPermissions RequiredThird Party Advisory
- http://drupalcode.org/project/simplenews.git/commitdiff/faec6a6Permissions RequiredThird Party Advisory
- http://www.openwall.com/lists/oss-security/2012/06/14/3Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/53839Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76143Third Party AdvisoryVDB Entry
- http://drupal.org/node/1619812Third Party Advisory
- http://drupal.org/node/1619818Third Party Advisory
- http://drupal.org/node/1619820Third Party Advisory
- http://drupal.org/node/1619848Third Party Advisory
- http://drupalcode.org/project/simplenews.git/commitdiff/36352c1Permissions RequiredThird Party Advisory
FAQ
What is CVE-2012-2724?
CVE-2012-2724 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is ...
How severe is CVE-2012-2724?
CVE-2012-2724 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2724?
Check the references section above for vendor advisories and patch information. Affected products include: Md-Systems Simplenews.