CVE-2012-2073: Kristof De Jaeger Bundle Copy

Medium severity, CVSS 6.0. EPSS: 1.8% chance of exploitation in the next 30 days.

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.

Affected products

Published 2012-08-14. Last modified 2026-06-16.