PT-2012-5418 · Drupal · Listhandler

Joshua Brauer

·

Published

2012-11-30

·

Updated

2013-01-30

·

CVE-2012-4470

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Listhandler module versions 6.x-1.x before 6.x-1.1 for Drupal
Description The issue concerns the Listhandler module for Drupal, where it fails to properly check permissions when importing emails. This allows remote comment authors to bypass access restrictions, potentially leading to unspecified impacts.
Recommendations For Listhandler module versions 6.x-1.x before 6.x-1.1, update to version 6.x-1.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4470

Affected Products

Listhandler