CVE-2012-2724

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.0:x
md-systemssimplenews
6.x-1.1:x
md-systemssimplenews
6.x-1.2:x
md-systemssimplenews
6.x-1.3:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.0:x
md-systemssimplenews
6.x-2.x:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
md-systemssimplenews
7.x-1.0:x
𝑥
= Vulnerable software versions