CVE-2012-2724

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
References
Link Resource
http://drupal.org/node/1619812 Third Party Advisory
http://drupal.org/node/1619818 Third Party Advisory
http://drupal.org/node/1619820 Third Party Advisory
http://drupal.org/node/1619848 Third Party Advisory
http://drupalcode.org/project/simplenews.git/commitdiff/36352c1 Permissions Required Third Party Advisory
http://drupalcode.org/project/simplenews.git/commitdiff/6d5704c Permissions Required Third Party Advisory
http://drupalcode.org/project/simplenews.git/commitdiff/faec6a6 Permissions Required Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/06/14/3 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/53839 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/76143 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:md-systems:simplenews:6.x-1.0:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta3:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta4:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta5:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc3:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc4:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc5:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc6:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.1:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.2:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-1.3:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.0:alpha1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.0:alpha2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.0:alpha3:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:6.x-2.x:dev:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:-:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:alpha1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:alpha2:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:beta1:*:*:*:drupal:*:*
cpe:2.3:a:md-systems:simplenews:7.x-1.0:beta2:*:*:*:drupal:*:*

History

No history.

Information

Published : 2020-01-09 20:15

Updated : 2024-02-04 20:39


NVD link : CVE-2012-2724

Mitre link : CVE-2012-2724

CVE.ORG link : CVE-2012-2724


JSON object : View

Products Affected

md-systems

  • simplenews
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor