CVE-2012-5586
Last modified
CVE-2012-5586 is a vulnerability of currently unknown severity. The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource.". EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Marc Ingram | Services | 6.x-3.0 | — |
| Marc Ingram | Services | 6.x-3.1 | — |
| Marc Ingram | Services | 6.x-3.2 | — |
| Marc Ingram | Services | 6.x-3.x | Dev |
| Marc Ingram | Services | 7.x-3.0 | — |
| Marc Ingram | Services | 7.x-3.1 | — |
| Marc Ingram | Services | 7.x-3.2 | — |
| Marc Ingram | Services | 7.x-3.3 | — |
| Marc Ingram | Services | 7.x-3.x | Dev |
References
- http://drupal.org/node/1853200Patch, Vendor Advisory
- http://drupal.org/node/1853200Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5586?
How severe is CVE-2012-5586?
How do I fix CVE-2012-5586?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-5580Format string vulnerability in the print_proxies function in…
- CVE-2012-5581Stack-based buffer overflow in tif_dir.c in LibTIFF before 4…
- CVE-2012-5582opendnssec misuses libcurl API9.8
- CVE-2012-5583phpCAS before 1.3.2 does not verify that the server hostname…
- CVE-2012-5584The Table of Contents module 6.x-3.x before 6.x-3.8 for Drup…
- CVE-2012-5585Cross-site scripting (XSS) vulnerability in the Mixpanel mod…
- CVE-2012-5587Cross-site scripting (XSS) vulnerability in the Email Field …
- CVE-2012-5588The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, wh…
- CVE-2012-5589The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x befo…
- CVE-2012-5590SQL injection vulnerability in the Webmail Plus module for D…
- CVE-2012-5591Cross-site scripting (XSS) vulnerability in the Zero Point m…
- CVE-2012-5592Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2012-5586?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
