CVE-2012-2724: Infoleak
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2724?
The severity of CVE-2012-2724 is rated as medium with a score of 5.3 on the CVSS scale.
What does CVE-2012-2724 expose?
CVE-2012-2724 exposes the email addresses of new mailing list subscribers when confirmation is required.
How can I fix CVE-2012-2724?
To fix CVE-2012-2724, update the Simplenews module to the latest version: 6.x-1.4, 6.x-2.0-alpha4, or 7.x-1.0-rc1 or newer.
What is affected by CVE-2012-2724?
CVE-2012-2724 affects the Simplenews module in Drupal versions prior to 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1.
What type of vulnerability is CVE-2012-2724 classified as?
CVE-2012-2724 is classified as an information leakage vulnerability.