CVE-2012-2299: Low severity ubercart currency conversion vulnerability
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2299?
CVE-2012-2299 is classified as a high-severity vulnerability due to the storage of passwords in plaintext.
How do I fix CVE-2012-2299?
To fix CVE-2012-2299, update the Ubercart module to version 6.x-2.8 or 7.x-3.1 or later.
Who is affected by CVE-2012-2299?
Users of Ubercart versions prior to 6.x-2.8 and 7.x-3.1 for Drupal are affected by CVE-2012-2299.
What impact does CVE-2012-2299 have on user data?
CVE-2012-2299 allows local users to gain access to sensitive information by retrieving stored plaintext passwords from the database.
Is there a workaround for CVE-2012-2299?
There are no recommended workarounds for CVE-2012-2299 other than upgrading the affected modules.