First published: Mon May 21 2012(Updated: )
The Contact Forms module 7.x-1.x before 7.x-1.2 for Drupal does not specify sufficiently restrictive permissions, which allows remote authenticated users with the "access the site-wide contact form" permission to modify the module settings via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Geoff Davies Contact Forms | =7.x-1.1 | |
Geoff Davies Contact Forms | =7.x-1.x-dev | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2340 has been classified as a moderate severity vulnerability due to its potential to allow unauthorized modification of module settings.
To fix CVE-2012-2340, you should upgrade the Contact Forms module to version 7.x-1.2 or later.
Users of the Contact Forms module version 7.x-1.1 or 7.x-1.x-dev on Drupal are affected by CVE-2012-2340.
The implications of CVE-2012-2340 include the risk of remote authenticated users being able to alter module settings, potentially compromising site integrity.
CVE-2012-2340 can be exploited by remote authenticated users who have the "access the site-wide contact form" permission.