PT-2012-5441 · Drupal · Mime Mail Module

Joshua Brauer

·

Published

2012-10-31

·

Updated

2013-03-02

·

CVE-2012-4495

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mime Mail module versions prior to 6.x-1.1
Description The issue allows remote authenticated users to send arbitrary files as attachments due to improper access restriction to files outside Drupal's publish files directory.
Recommendations For Mime Mail module versions prior to 6.x-1.1, update to version 6.x-1.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4495

Affected Products

Mime Mail Module