Medium severity4.3NVD Advisory· Published Feb 8, 2020· Updated Jun 16, 2026
CVE-2012-5570
CVE-2012-5570
Description
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:basic_webmail_project:basic_webmail:6.x-1.0:*:*:*:*:drupal:*:*+ 2 more
- cpe:2.3:a:basic_webmail_project:basic_webmail:6.x-1.0:*:*:*:*:drupal:*:*
- cpe:2.3:a:basic_webmail_project:basic_webmail:6.x-1.1:*:*:*:*:drupal:*:*
- cpe:2.3:a:basic_webmail_project:basic_webmail:6.x-1.x:dev:*:*:*:drupal:*:*
- Range: <6.x-1.2
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2012/11/20/4nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2012/11/27/2nvdMailing ListThird Party Advisory
- drupal.org/node/1808616nvdRelease NotesVendor Advisory
- www.drupal.org/node/1808852nvdVendor Advisory
News mentions
0No linked articles in our index yet.