← Back

CVE-2012-5588

nvd nist
Published: Dec 26, 2012Modified: Apr 29, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

Affected (5)

Products: Epiqo: Email
1 product
Email
Configuration A
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Epiqo
Version 6.x-1.0
Version 6.x-1.0 rc1
Version 6.x-1.1
Version 6.x-1.2
Version 6.x-1.x dev
Running on/withPlatform Versions
Drupal
Drupal
All versions

Related CWEs

References (6)

Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.