SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-5588

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email…

LOW 2.6EPSS 1.16%

Does this matter?

Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.

Description

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
1.16% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
epiqo/email
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.