Drupal · Webform Report · CVE-2019-25012
**Name of the Vulnerable Software and Affected Versions**
Webform Report project versions 7.x-1.x-dev
**Description**
The issue allows remote attackers to view submissions by visiting the "/rss.xml" page. This project is not covered by Drupal's security advisory policy.
**Recommendations**
For version 7.x-1.x-dev, as a temporary workaround, consider restricting access to the "/rss.xml" page until a patch is available.