CVE-2012-1590: Drupal
Medium severity, CVSS 4.0. EPSS: 1.4% chance of exploitation in the next 30 days.
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.
Affected products
- Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
Published 2012-10-01. Last modified 2026-06-16.