First published: Wed Mar 27 2013(Updated: )
The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
David Alkire Email2image | =6.x-1.x | |
David Alkire Email2image | =6.x-2.x | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0257 is classified as a medium severity vulnerability due to unauthorized access to sensitive user information.
To resolve CVE-2013-0257, update the email2image module to version 6.x-2.x or later.
CVE-2013-0257 affects email2image module versions 6.x-1.x and 6.x-2.x.
Yes, CVE-2013-0257 can be exploited remotely, allowing attackers to access user email addresses.
CVE-2013-0257 affects the Drupal content management system when using the vulnerable email2image module.