Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6975-wf7j-2rx4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

EPSS

Процентиль: 43%
0.00208
Низкий

Связанные уязвимости

nvd
больше 12 лет назад

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

EPSS

Процентиль: 43%
0.00208
Низкий