CVE-2012-5588
Estado: ModificadaBaja (2.6)—
The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.16%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-5588",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-12-26T17:55:02.283",
"references": [
{
"url": "http://drupal.org/node/1852612",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1853214",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/11/29/2",
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1852612",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/1853214",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/11/29/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors."
},
{
"lang": "es",
"value": "El módulo Email Field v6.x-1.x antes de v6.x-1.3 para Drupal, cuando se utiliza un módulo de permisos de campos y el formateador de campos de contacto esta puesto a modo de pantalla completa o teaser, no comprueba correctamente los permisos, lo que permite a atacantes remotos a enviar por correo electrónico la dirección almacenada a través de vectores no especificados.\r\n"
}
],
"lastModified": "2026-06-16T23:47:03.623",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:epiqo:email:6.x-1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6EB3FB6-5AB6-4A82-92AE-84DC111A30F2"
},
{
"criteria": "cpe:2.3:a:epiqo:email:6.x-1.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B8A0C0B-A1E1-455E-8AC8-5574350DFDE7"
},
{
"criteria": "cpe:2.3:a:epiqo:email:6.x-1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D1DFB2D-8E5B-46C4-902A-AD303CD86BEC"
},
{
"criteria": "cpe:2.3:a:epiqo:email:6.x-1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD2A121F-00E5-4F83-B600-10AFB6E0D188"
},
{
"criteria": "cpe:2.3:a:epiqo:email:6.x-1.x:dev:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D0DE333-B43B-4123-866F-522D4A265B59"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secalert@redhat.com"
}