CVE-2012-2724

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
References
Link Resource
https://exchange.xforce.ibmcloud.com/vulnerabilities/76143 Third Party Advisory VDB Entry
http://drupalcode.org/project/simplenews.git/commitdiff/faec6a6 Permissions Required Third Party Advisory
http://www.securityfocus.com/bid/53839 Third Party Advisory VDB Entry
http://drupal.org/node/1619848 Third Party Advisory
http://drupal.org/node/1619820 Third Party Advisory
http://drupal.org/node/1619818 Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/06/14/3 Mailing List Third Party Advisory
http://drupalcode.org/project/simplenews.git/commitdiff/36352c1 Permissions Required Third Party Advisory
http://drupalcode.org/project/simplenews.git/commitdiff/6d5704c Permissions Required Third Party Advisory
http://drupal.org/node/1619812 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:md-systems:simplenews:6.x-1.0:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta3:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta4:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta5:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc3:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc4:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc5:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:alpha1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.2:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:alpha2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc6:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.1:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:beta1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.3:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:beta2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.x:dev:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.0:alpha1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.0:alpha2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.0:alpha3:*:*:*:drupal:*:*

Information

Published : 2020-01-09 12:15

Updated : 2020-01-28 11:42


NVD link : CVE-2012-2724

Mitre link : CVE-2012-2724


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

md-systems

  • simplenews