Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-5588


The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.


Published

2012-12-26T17:55:02.283

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.6 (LOW)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

4.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application epiqo email 6.x-1.0 Yes
Application epiqo email 6.x-1.0 Yes
Application epiqo email 6.x-1.1 Yes
Application epiqo email 6.x-1.2 Yes
Application epiqo email 6.x-1.x Yes
Application drupal drupal - No

References