Information Disclosure Vulnerability in Simplenews Module for Drupal

Information Disclosure Vulnerability in Simplenews Module for Drupal

CVE-2012-2724 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.

Learn more about our Web Application Penetration Testing UK.