The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2012/11/29/2 | |
| http://drupal.org/node/1852612 | Patch | 
| http://drupal.org/node/1853214 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2012-12-26 09:55
Updated : 2012-12-26 21:00
NVD link : CVE-2012-5588
Mitre link : CVE-2012-5588
JSON object : View
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
Products Affected
                drupal
- drupal
 
epiqo


