Vulnerabilities > Basic Webmail Project

DATE CVE VULNERABILITY TITLE RISK
2020-02-08 CVE-2012-5570 Information Exposure vulnerability in Basic Webmail Project Basic Webmail 6.X1.0/6.X1.1/6.X1.X
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
network
low complexity
basic-webmail-project CWE-200
4.0
2012-12-03 CVE-2012-5569 Cross-Site Scripting vulnerability in multiple products
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
4.3