PT-2012-4193 · Drupal · Ubercart Product Keys

Kurt Seifried

·

Published

2012-06-27

·

Updated

2017-08-29

·

CVE-2012-2702

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ubercart Product Keys module versions 6.x-1.x before 6.x-1.1 for Drupal
Description The issue allows remote attackers to read all unassigned product keys under certain conditions related to the uid. This occurs because the module does not properly check access for product keys.
Recommendations For Ubercart Product Keys module versions 6.x-1.x before 6.x-1.1, update to version 6.x-1.1 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2702

Affected Products

Ubercart Product Keys