Vulnerability Description
The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webform Report Project | Webform Report | 7.x-1.x-dev |
Related Weaknesses (CWE)
References
- https://www.drupal.org/project/webform_report/issues/3101410Vendor Advisory
- https://www.drupal.org/project/webform_report/issues/3101410Vendor Advisory
FAQ
What is CVE-2019-25012?
CVE-2019-25012 is a vulnerability with a CVSS score of 7.5 (HIGH). The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.
How severe is CVE-2019-25012?
CVE-2019-25012 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25012?
Check the references section above for vendor advisories and patch information. Affected products include: Webform Report Project Webform Report.