CVE-2012-2724

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.1:x
md-systemssimplenews
6.x-1.2:x
md-systemssimplenews
6.x-1.3:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.x:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
𝑥
= Vulnerable software versions