CVE Vulnerabilities

CVE-2012-5586

Published: Dec 26, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the access user profiles permission to access arbitrary users emails via vectors related to the user index method and the path to the user resource.

Affected Software

NameVendorStart VersionEnd Version
ServicesMarc_ingram6.x-3.0 (including)6.x-3.0 (including)
ServicesMarc_ingram6.x-3.0-alpha1 (including)6.x-3.0-alpha1 (including)
ServicesMarc_ingram6.x-3.0-beta1 (including)6.x-3.0-beta1 (including)
ServicesMarc_ingram6.x-3.0-beta2 (including)6.x-3.0-beta2 (including)
ServicesMarc_ingram6.x-3.0-rc1 (including)6.x-3.0-rc1 (including)
ServicesMarc_ingram6.x-3.0-rc2 (including)6.x-3.0-rc2 (including)
ServicesMarc_ingram6.x-3.0-rc3 (including)6.x-3.0-rc3 (including)
ServicesMarc_ingram6.x-3.0-rc4 (including)6.x-3.0-rc4 (including)
ServicesMarc_ingram6.x-3.0-unstable1 (including)6.x-3.0-unstable1 (including)
ServicesMarc_ingram6.x-3.0-unstable2 (including)6.x-3.0-unstable2 (including)
ServicesMarc_ingram6.x-3.0-unstable3 (including)6.x-3.0-unstable3 (including)
ServicesMarc_ingram6.x-3.1 (including)6.x-3.1 (including)
ServicesMarc_ingram6.x-3.2 (including)6.x-3.2 (including)
ServicesMarc_ingram6.x-3.x-dev (including)6.x-3.x-dev (including)

References