CVE Vulnerabilities

CVE-2012-4495

Published: Oct 31, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupals publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

Affected Software

NameVendorStart VersionEnd Version
MimemailMime_mail_module_project6.x-1.0 (including)6.x-1.0 (including)
MimemailMime_mail_module_project6.x-1.0-alpha1 (including)6.x-1.0-alpha1 (including)
MimemailMime_mail_module_project6.x-1.0-alpha2 (including)6.x-1.0-alpha2 (including)
MimemailMime_mail_module_project6.x-1.0-alpha3 (including)6.x-1.0-alpha3 (including)
MimemailMime_mail_module_project6.x-1.0-alpha4 (including)6.x-1.0-alpha4 (including)
MimemailMime_mail_module_project6.x-1.0-alpha5 (including)6.x-1.0-alpha5 (including)
MimemailMime_mail_module_project6.x-1.0-alpha6 (including)6.x-1.0-alpha6 (including)
MimemailMime_mail_module_project6.x-1.0-alpha7 (including)6.x-1.0-alpha7 (including)
MimemailMime_mail_module_project6.x-1.0-alpha8 (including)6.x-1.0-alpha8 (including)
MimemailMime_mail_module_project6.x-1.0-beta1 (including)6.x-1.0-beta1 (including)
MimemailMime_mail_module_project6.x-1.0-beta2 (including)6.x-1.0-beta2 (including)
MimemailMime_mail_module_project6.x-1.x-dev (including)6.x-1.x-dev (including)

References