Lucene search

K

Simplenews Security Vulnerabilities

cve
cve

CVE-2012-2724

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.

5.3CVSS

5.2AI Score

0.01EPSS

2020-01-09 08:15 PM
51
cve
cve

CVE-2013-4447

Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.

5.9AI Score

0.003EPSS

2013-11-01 03:55 PM
28