CVE-2012-4553

medium
Published 2012-11-11 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupalcode.org/project/drupal.git/commit/b912710

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupal.org/node/1815912

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupal.org/node/1815904

Application impact

VendorProductVersionsFixed
drupaldrupal7.0
drupaldrupal7.1
drupaldrupal7.2
drupaldrupal7.3
drupaldrupal7.4
drupaldrupal7.5
drupaldrupal7.6
drupaldrupal7.7
drupaldrupal7.8
drupaldrupal7.9
drupaldrupal7.10
drupaldrupal7.11
drupaldrupal7.12
drupaldrupal7.13
drupaldrupal7.14
drupaldrupal7.15

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.