SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2702

The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.

MEDIUM 5.0EPSS 2.58%

Does this matter?

Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.

Description

The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.58% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
tony freixas/ubercart product keys
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.