CVE Vulnerabilities

CVE-2012-2702

Published: Jun 27, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.

Affected Software

NameVendorStart VersionEnd Version
Ubercart_product_keysTony_freixas6.x-1.0 (including)6.x-1.0 (including)
Ubercart_product_keysTony_freixas6.x-1.0-alpha1 (including)6.x-1.0-alpha1 (including)
Ubercart_product_keysTony_freixas6.x-1.0-alpha2 (including)6.x-1.0-alpha2 (including)
Ubercart_product_keysTony_freixas6.x-1.0-alpha3 (including)6.x-1.0-alpha3 (including)
Ubercart_product_keysTony_freixas6.x-1.0-beta1 (including)6.x-1.0-beta1 (including)
Ubercart_product_keysTony_freixas6.x-1.0-rc1 (including)6.x-1.0-rc1 (including)
Ubercart_product_keysTony_freixas6.x-1.0-rc2 (including)6.x-1.0-rc2 (including)

References