CVE-2012-5537
medium
CVSS v3
—
CVSS v2
6.0
VIR risk
6.0
Description
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://drupal.org/node/1789284
Vendor advisory: secalert@redhat.com — http://drupal.org/node/1789274
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| simplenews_scheduler_project | simplenews_scheduler | 6.x-2.0 | |
| simplenews_scheduler_project | simplenews_scheduler | 6.x-2.1 | |
| simplenews_scheduler_project | simplenews_scheduler | 6.x-2.2 | |
| simplenews_scheduler_project | simplenews_scheduler | 6.x-2.3 | |
| simplenews_scheduler_project | simplenews_scheduler | 6.x-2.x | |
| drupal | drupal | - | |
References
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.