CVE-2012-2724

EUVD-2012-2704
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.1:x
md-systemssimplenews
6.x-1.2:x
md-systemssimplenews
6.x-1.3:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.x:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
𝑥
= Vulnerable software versions