The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://drupal.org/node/1834868 | patch vendor advisory |
http://drupal.org/node/1774252 | patch |
http://drupal.org/node/1768632 | |
http://www.openwall.com/lists/oss-security/2012/11/20/4 | mailing list |