CVE-2012-1591: Drupal
Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
Affected products
- Drupal Drupal: version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; …
Published 2012-10-01. Last modified 2026-06-16.