Vulnerability Details CVE-2012-5554
The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.0%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2012-5554
-
cpe:2.3:a:coleman_watts:webform_civicrm:7.x-3.0
-
cpe:2.3:a:coleman_watts:webform_civicrm:7.x-3.1
-
cpe:2.3:a:coleman_watts:webform_civicrm:7.x-3.x
-
cpe:2.3:a:drupal:drupal:-