CVE-2012-5588

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:epiqo:email:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:epiqo:email:6.x-1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:epiqo:email:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:epiqo:email:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:epiqo:email:6.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-12-26 17:55

Updated : 2023-12-10 11:16


NVD link : CVE-2012-5588

Mitre link : CVE-2012-5588

CVE.ORG link : CVE-2012-5588


JSON object : View

Products Affected

epiqo

  • email

drupal

  • drupal
CWE
CWE-264

Permissions, Privileges, and Access Controls